Trojan

Win32/TrojanDownloader.Autoit.PFK (file analysis)

Malware Removal

The Win32/TrojanDownloader.Autoit.PFK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Autoit.PFK virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Win32/TrojanDownloader.Autoit.PFK?


File Info:

name: 74046BDFF9059241E52F.mlw
path: /opt/CAPEv2/storage/binaries/0f5891a7ff4f49086c402c7c0be2ba9994b958adc3ddcf5a6845c09767c8eaed
crc32: 27A9C78A
md5: 74046bdff9059241e52f89e9ac5c32c4
sha1: a8619202793c8e1623fe89da79e30a93b9033a21
sha256: 0f5891a7ff4f49086c402c7c0be2ba9994b958adc3ddcf5a6845c09767c8eaed
sha512: 46e1979b5c5acccfd73a9e4e783f97a03f99c581e520803d51257347f04ee14123bac6c5129646416b082f01d47a878897e8d083e91dc9c745b5a5915c3b6206
ssdeep: 24576:qAHnh+eWsN3skA4RV1Hom2KXMmHaSUq5:9h+ZkldoPK8YaSV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T120058B0273D1C036FFABA2739B6AF64156BC79254133852F13981DB9BD701B2263E663
sha3_384: 63b48746ea4c096d919c98889fd6b82f3ac85b9114b1c141a99cc1779428f4cacd5dcf89bb6277cb8a1e105d153f90f1
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2021-12-08 19:20:51

Version Info:

Translation: 0x0809 0x04b0

Win32/TrojanDownloader.Autoit.PFK also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop19.13512
MicroWorld-eScanAIT:Trojan.Nymeria.5019
FireEyeGeneric.mg.74046bdff9059241
CAT-QuickHealTrojandownloader.Generic
McAfeeRDN/Generic Dropper
CylanceUnsafe
AlibabaTrojanDropper:Script/Generic.632407a2
VirITTrojan.Win32.MulDrop8.BMDO
ESET-NOD32a variant of Win32/TrojanDownloader.Autoit.PFK
TrendMicro-HouseCallTROJ_GEN.R002C0PLC21
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Dropper.Script.Sysn.gen
BitDefenderAIT:Trojan.Nymeria.5019
AvastWin32:Malware-gen
TencentWin32.Trojan-downloader.Generic.Aedw
Ad-AwareAIT:Trojan.Nymeria.5019
EmsisoftAIT:Trojan.Nymeria.5019 (B)
TrendMicroTROJ_GEN.R002C0PLC21
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-S
GDataAIT:Trojan.Nymeria.5019 (2x)
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Nymeria.865792
MicrosoftProgram:Win32/Wacapew.C!ml
VBA32Trojan.Wacatac
ALYacAIT:Trojan.Nymeria.5019
APEXMalicious
MAXmalware (ai score=89)
FortinetW32/PossibleThreat
AVGWin32:Malware-gen

How to remove Win32/TrojanDownloader.Autoit.PFK?

Win32/TrojanDownloader.Autoit.PFK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment