Trojan

Win32/TrojanDownloader.Autoit.PFH removal guide

Malware Removal

The Win32/TrojanDownloader.Autoit.PFH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Autoit.PFH virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/TrojanDownloader.Autoit.PFH?


File Info:

name: 8115C18E4A3C344F0271.mlw
path: /opt/CAPEv2/storage/binaries/f42def3584cbdd93edb8c9b22a6334826f90599deff3ae35375fd8606a64fb9d
crc32: 7CEADD52
md5: 8115c18e4a3c344f0271bcb940c06735
sha1: 8f06bf3889b78eeaeb7c88de5a3598bb559292e0
sha256: f42def3584cbdd93edb8c9b22a6334826f90599deff3ae35375fd8606a64fb9d
sha512: 1511c8f35033634bbe347b02a7666502729c3fd533b8c84bf11f4a71ce5bcea1818aa99d8896739027bec6c2c4ae744dd0de7f816543342a928cc96772a2fab7
ssdeep: 24576:rAHnh+eWsN3skA4RV1Hom2KXMmHa/1IBs5C:Gh+ZkldoPK8YaNI4C
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168159D1273D2D036FFAB92739F5AF20696BD69250123852F13981DB9BD701B1233E663
sha3_384: a2879d09c582b1e6edc43e0d458e2dfc69dfe3612fd74ac33d1e68c990040f04128a08f9f1efe5e87c300b258afd93f8
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2021-12-05 23:34:30

Version Info:

0: [No Data]

Win32/TrojanDownloader.Autoit.PFH also known as:

LionicHacktool.Win32.Gamehack.3!e
DrWebTrojan.MulDrop19.12878
MicroWorld-eScanTrojan.GenericKD.47588639
FireEyeTrojan.GenericKD.47588639
CAT-QuickHealTrojanSpy.Stealer
McAfeeRDN/RedLineStealer
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/Stealer.99879883
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.889b78
VirITTrojan.Win32.Injector.CTNN
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Autoit.PFH
Paloaltogeneric.ml
ClamAVWin.Malware.Autoit-9849407-0
KasperskyTrojan-Spy.Win32.Stealer.aope
BitDefenderTrojan.GenericKD.47588639
AvastWin32:Trojan-gen
TencentWin32.Trojan.Falsesign.Dwiv
Ad-AwareTrojan.GenericKD.47588639
EmsisoftTrojan.GenericKD.47588639 (B)
TrendMicroTrojan.Win32.STEALER.USMANL721
McAfee-GW-EditionRDN/RedLineStealer
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.AutoIt
GDataTrojan.GenericKD.47588639
AviraHEUR/AGEN.1100130
MAXmalware (ai score=84)
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Autoit.890336
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Stealer.C4823928
VBA32TrojanSpy.Stealer
ALYacTrojan.GenericKD.47588639
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTrojan.Win32.STEALER.USMANL721
RisingTrojan.Obfus/Autoit!1.C774 (CLASSIC)
FortinetW32/Autoit.PFH!tr.dldr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/TrojanDownloader.Autoit.PFH?

Win32/TrojanDownloader.Autoit.PFH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment