How to remove autoit3_x64.exe

autoit3_x64.exe

The module autoit3_x64.exe has been detected as Trojan.CoinMiner

autoit3_x64.exe
Product Name:

AutoIt v3 Script

Company Name:

AutoIt Team

MD5: de43b312c11513b6975b9940d06d303b
Size: 1 MB
First Published: 2017-12-23 14:06:54 (7 years ago)
Latest Published: 2025-02-03 23:01:20 (5 months ago)
Status: Trojan.CoinMiner (on last analysis)
Analysis Date: 2025-02-03 23:01:20 (5 months ago)
Signed By: AutoIt Consulting Ltd
Status: Valid
%sysdrive%\newcpuspeed\newcpuspeedcheck\workers
%sysdrive%\newcpuspeed\workers
%sysdrive%\newcpuspeedcheck\newcpuspeedcheck\workers
%sysdrive%\newcpuspeedcheck\workers
%programfiles%
%sysdrive%\notifications\newcpuspeedcheck\workers
%sysdrive%\dcim\newcpuspeedcheck\workers
%sysdrive%\.cocodata\newcpuspeedcheck\workers
%sysdrive%\musica\newcpuspeedcheck\workers
%sysdrive%\.androidck\newcpuspeedcheck\workers
cpuchecker.exe
autoit3_x64.exe
AutoIt3.exe
AU3381.exe
AutoIt3_x64.exe
Peru 59.5%
Bolivia 11.0%
Russia 4.3%
Taiwan 4.3%
Ecuador 2.1%
Mexico 1.8%
Colombia 1.8%
Argentina 1.8%
Vietnam 1.8%
Brazil 1.5%
France 1.2%
United States 1.2%
Thailand 1.2%
Iran 1.2%
Portugal 0.9%
Madagascar 0.6%
Finland 0.6%
Poland 0.6%
Netherlands 0.6%
Turkey 0.6%
Germany 0.3%
Sweden 0.3%
Italy 0.3%
Windows 10 43.6%
Windows 7 34.5%
Windows 8.1 19.8%
Windows Embedded 8.1 1.2%
Windows XP 0.6%
Windows Vista 0.3%
Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x0002fe64

PE Sections:

Name Size of data MD5
.text 692736 c83c688ee0d637f898ed87391bbdf5dc
.rdata 195584 f8378ea08dde71401c6a47874a977f72
.data 24064 0854738a2fd15c1f4a6d5c121979b421
.pdata 27136 18bdefe792584ce898b031515ffff6b4
.rsrc 108544 0ad0bf19bad81bc774c0031e03e0702f
.reloc 3072 a09769711fc058127866bcb206d75d0f

More information:

Download GridinSoft Anti-Malware - Removal tool for autoit3_x64.exe
­