Home Malware Programs Trojans TrojanDownloader:AutoIt/Fadef

TrojanDownloader:AutoIt/Fadef

Posted: September 1, 2015

Threat Metric

Ranking: 17,208
Threat Level: 9/10
Infected PCs: 2,091
First Seen: September 1, 2015
Last Seen: October 7, 2023
OS(es) Affected: Windows

TrojanDownloader:AutoIt/Fadef is a hazardous type of malware, which may infiltrate your system regardless of the version of your Windows. Even if you are not an expert, just seeing the name of this cyber threat will be enough to understand why it is so dangerous. TrojanDownloader:AutoIt/Fadef doesn't cause some particular problems immediately after it gets access to your PC. Instead, its primary function is to allow its operators to load some additional harmful applications of their choice. The typical distribution methods for such programs are just a few, and TrojanDownloader:AutoIt/Fadef follows the beaten track. It may reach your machine if you open files attached to some spam emails. In case you are redirected to some compromised webpage and download some software from there, you may also load the Trojan. Once it gets in, TrojanDownloader:AutoIt/Fadef creates a few files that allow it to perform its tasks. If you make some efforts, you may be able to detect %ProgramData%\administratorsalva\dh.dll and %ProgramData%\administratorsalva\rotartsinimdadefense.exe. The harmful tool also changes the HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry key. The objective of these modifications is twofold. The malware will launch itself automatically at system startup, and the conventional tools will have a really hard time when trying to detect and delete the infection. Once all of these alterations are in place, TrojanDownloader:AutoIt/Fadef creates a connection towards Command and Control (C&C) servers, which happens in the background. From this moment on, the hackers may download any cyber threat to your PC. To prevent their malicious plans and delete TrojanDownloader:AutoIt/Fadef, you need to scan your PC with a professional malware removal solution.

Loading...