Trojan

Win32/TrojanDownloader.Autoit.PEN removal tips

Malware Removal

The Win32/TrojanDownloader.Autoit.PEN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Autoit.PEN virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

a.tmp.ninja
apps.identrust.com
crl.identrust.com
x1.c.lencr.org

How to determine Win32/TrojanDownloader.Autoit.PEN?


File Info:

crc32: 2D08EF2E
md5: 5dee264e7b7d41cb0f579860a618c144
name: 5DEE264E7B7D41CB0F579860A618C144.mlw
sha1: 9c7aaab804bf2416e7e2ca87cd088305fdef8b29
sha256: e9714695528eb1f8786fe8a7250f952f23b3205a4e2a60073668717eb2f5dc2b
sha512: f2e1a598eec682a027ca6e69ca8395de9dd7a2420b20b44a5c5dda5ab45ece96223c476ed0b412220e20f91fd02981bfa06bdd31cd17d9bfd0c36826b8f3d88c
ssdeep: 6144:S4XrK9PX7Fp6Gh2wWRGl0EDDf1PisZQ5rAGQwg1QtP1f4paaYlsdcaMJEdbI0Pz:JXe9PPlowWX0t6mOQwg1Qd15CcYk0We
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

Win32/TrojanDownloader.Autoit.PEN also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Auzenpak.4!c
CylanceUnsafe
SangforTrojan.Win32.Auzenpak.gy
CyrenW32/Trojan.GFPJ-8809
SymantecTrojan Horse
ESET-NOD32Win32/TrojanDownloader.Autoit.PEN
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Auzenpak.gx
BitDefenderTrojan.GenericKD.46876408
MicroWorld-eScanTrojan.GenericKD.46876408
Ad-AwareTrojan.GenericKD.46876408
SophosMal/Generic-S + Troj/Inject-HBF
ComodoMalware@#2x5sje3l5165a
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.5dee264e7b7d41cb
EmsisoftTrojan.GenericKD.46876408 (B)
WebrootW32.Dropper.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/StopCrypt!ml
ZoneAlarmTrojan.Win32.Auzenpak.gx
GDataWin32.Trojan.Agent.TCQNNT
AhnLab-V3Trojan/Win.Generic.C4609890
McAfeeArtemis!5DEE264E7B7D
MAXmalware (ai score=82)
IkarusWin32.SuspectCrc
FortinetAutoIt/Injector.BFC6!tr
AVGFileRepMalware

How to remove Win32/TrojanDownloader.Autoit.PEN?

Win32/TrojanDownloader.Autoit.PEN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment