Trojan

How to remove “Win32/TrojanDownloader.Autoit.OQW”?

Malware Removal

The Win32/TrojanDownloader.Autoit.OQW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Autoit.OQW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/TrojanDownloader.Autoit.OQW?


File Info:

crc32: 484AC431
md5: 0515ff39bf57a415c764bbef3c4fa546
name: 0515FF39BF57A415C764BBEF3C4FA546.mlw
sha1: 156be8a73a807f3c4321772799396811c6155b6d
sha256: 1a2a3788a68ff0db452b3d3d0da84f880b085a9547d9ae136ffa2363a96f4024
sha512: d24c8d8aae38fcaf783d3c40ec6ee07dbf3bede62b683aa1826469c1b62bbdc559b9e45f8e6fd149d369113db46add82ee2fdb715ce82c6144e31ef1537bb432
ssdeep: 24576:HthEVaPqLslws7GkyIk7U8nE5Xw2Jh71lBAAbO6z:LEVUcsTqL7ZExzfOCZz
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: image viewer
FileVersion: 2.22.0.0
Comments: image viewer
Translation: 0x0809 0x04b0

Win32/TrojanDownloader.Autoit.OQW also known as:

K7AntiVirusTrojan-Downloader ( 0053fefc1 )
DrWebTrojan.DownLoader27.12871
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.31322131
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Generic.7174a3ca
K7GWTrojan-Downloader ( 0053fefc1 )
Cybereasonmalicious.9bf57a
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/TrojanDownloader.Autoit.OQW
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Dropper.Win32.Sysn.ckff
BitDefenderTrojan.GenericKD.31322131
NANO-AntivirusTrojan.Win32.Sysn.fkmnso
ViRobotTrojan.Win32.Z.Autoit.990413
MicroWorld-eScanTrojan.GenericKD.31322131
TencentWin32.Trojan-dropper.Sysn.Chh
Ad-AwareTrojan.GenericKD.31322131
SophosMal/Generic-S
ComodoMalware@#38fb0gvi6c9v8
BitDefenderThetaAI:Packer.B0AA19AC17
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WH121
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeTrojan.GenericKD.31322131
EmsisoftTrojan.GenericKD.31322131 (B)
WebrootW32.Malware.Gen
AviraDR/AutoIt.Gen
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASBOL.C6A4
MicrosoftTrojan:Win32/Occamy.C1A
ZoneAlarmTrojan-Dropper.Win32.Sysn.ckff
GDataTrojan.GenericKD.31322131
AhnLab-V3Malware/Win32.Generic.C2865653
VBA32TrojanDropper.Sysn
MAXmalware (ai score=100)
TrendMicro-HouseCallTROJ_GEN.R002C0WH121
IkarusTrojan-Downloader.Win32.AutoIt
FortinetW32/Autoit.OQW!tr.dldr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/TrojanDownloader.Autoit.OQW?

Win32/TrojanDownloader.Autoit.OQW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment