Associated Malware Groups
The unsafe files using this name are associated with the malware group:
File Behavior
AUTOIT3.EXE has been seen to perform the following behavior:
- The Process is packed and/or encrypted using a software packing process
- Executes a Process
- Terminates Processes
- Adds a Registry Key (RUN) to auto start Programs on system start up
- Writes to another Process's Virtual Memory (Process Hijacking)
- Disables Access to the Task Manager built into Windows
- Modifies Windows Security Policies to restrict/expand User Privileges on the machine
- Can communicate with other computer systems using HTTP protocols
- This process creates other processes on disk
- Registers a Dynamic Link Library File
- This Process Deletes Other Processes From Disk
- Communicates with other computers using FTP connections
- Creates a TCP port which listens and is available for communication initiated by other computers
- Creates system tray popups, messages, errors and security warnings
AUTOIT3.EXE has been the subject of the following behavior:
- Created as a process on disk
- Copied to multiple locations on the system
- Changes to the file command map within the registry
- Executed as a Process
- Deleted as a process from disk
- Terminated as a Process
- Has code inserted into its Virtual Memory space by other programs
- Executed from Temporary Folders
Country Of Origin
The filename AUTOIT3.EXE was first seen on Jun 2 2007 in the following geographical regions of the Prevx community:
- on Jun 2 2007
- Europe on Jun 2 2007
- The United Kingdom on Feb 6 2010
File Name Aliases
AUTOIT3.EXE can also use the following file names:
- AUT17.TMP
- 17975817.EXE
- 46044777.EXE
Filesizes
The following file size has been seen:
- 403,968 bytes
- 731,648 bytes
- 171,520 bytes
- 461,568 bytes
File Type
The filename AUTOIT3.EXE refers to many versions of an executable program.
PCMag.com Editors' Choice Award Logo is a trademark of Ziff Davis Publishing Holdings Inc. Used under license.