Trojan

Win32/TrojanDownloader.Autoit.NRZ (file analysis)

Malware Removal

The Win32/TrojanDownloader.Autoit.NRZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Autoit.NRZ virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to disable UAC

How to determine Win32/TrojanDownloader.Autoit.NRZ?


File Info:

crc32: B3072A00
md5: 86a62f9da83790e6df10e3944545d970
name: 86A62F9DA83790E6DF10E3944545D970.mlw
sha1: 628af126001cb40710cd99ed5ae3ce52254a6193
sha256: 2670c02181d8b067094f6dfb61ff7cdb1cbebc8e5eb310e9efa1a1109e6eaecd
sha512: 9f11ceb515845e23a3a40a337d9c5e3263c162e5de5b52d48852b64e967765c771b6d558fec68ecfb401a5f9eceaef501e5998e2ecf4a6ef386c0905074c1524
ssdeep: 12288:uXe9PPlowWX0t6mOQwg1Qd15CcYk0We1qRMr/oYpOySic0jL:DhloDX0XOf48ijoyfX
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Adobe
ProductVersion: 3.3.10.2
FileVersion: 13.0.2.1
Comments: http://www.autoitscript.com/autoit3/
FileDescription: Flash Player
Translation: 0x0809 0x04b0

Win32/TrojanDownloader.Autoit.NRZ also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.43730470
FireEyeTrojan.GenericKD.43730470
ALYacTrojan.GenericKD.43730470
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Blocker.j!c
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
BitDefenderTrojan.GenericKD.43730470
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.da8379
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Blocker.emka
AlibabaRansom:Win32/Blocker.f6fda3f2
NANO-AntivirusTrojan.Win32.Blocker.dacgdv
Ad-AwareTrojan.GenericKD.43730470
EmsisoftTrojan.GenericKD.43730470 (B)
ComodoMalware@#20vvve4vl6oq0
F-SecureHeuristic.HEUR/AGEN.1114577
DrWebTrojan.FakeAV.19179
ZillyaTrojan.Blocker.Win32.19626
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.hc
SophosMal/Generic-S
IkarusTrojan-Ransom.Blocker
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1114577
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Inject
MicrosoftTrojan:Win32/Ymacco.AA07
ArcabitTrojan.Generic.D29B4626
AhnLab-V3Malware/Win32.Generic.C430522
ZoneAlarmTrojan-Ransom.Win32.Blocker.emka
GDataTrojan.GenericKD.43730470
CynetMalicious (score: 85)
ESET-NOD32a variant of Win32/TrojanDownloader.Autoit.NRZ
McAfeeArtemis!86A62F9DA837
VBA32TrojanRansom.Blocker
MalwarebytesMalware.Heuristic.1003
TencentMalware.Win32.Gencirc.114bbca7
eGambitUnsafe.AI_Score_99%
FortinetW32/Blocker.EMKA!tr
Qihoo-360Win32/Ransom.Blocker.HgIASOgA
PandaTrj/OCJ.F

How to remove Win32/TrojanDownloader.Autoit.NRZ?

Win32/TrojanDownloader.Autoit.NRZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment