Malware

AutoIt:Injector-JF [Trj] malicious file

Malware Removal

The AutoIt:Injector-JF [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AutoIt:Injector-JF [Trj] virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Clears web history

Related domains:

z.whorecord.xyz
a.tomx.xyz
daya4659.ddns.net

How to determine AutoIt:Injector-JF [Trj]?


File Info:

crc32: 4FB7119B
md5: 6da885209c69dc2a5c77bbc5e4b476d4
name: upload_file
sha1: a9591b04e8e4328ba372157c044f97b6b5407dd3
sha256: c2e9e9a56538ab2864d2e40db3b9af0749e1cb9aed569106c6a5e24b0c94accb
sha512: 63564fa527cdc96e62f4ca5dfe283aedd60534a376338aec97472f1fd98b7fec2845731e35c89c21e9ed73685f7c9148e988f14b2a8e045f412c981555cc8d19
ssdeep: 24576:yAHnh+eWsN3skA4RV1Hom2KXMmHaLIahgxY3b55:1h+ZkldoPK8YaLDN5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: winver
FileVersion: 385.28.742.705
CompanyName: control
ProductName: CameraCaptureUI
ProductVersion: 130.164.941.861
FileDescription: AudioEndpointBuilder
OriginalFilename: FlashUtil64_31_0_0_153_Plugin.exe
Translation: 0x0409 0x04b0

AutoIt:Injector-JF [Trj] also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34623556
FireEyeGeneric.mg.6da885209c69dc2a
CAT-QuickHealTrojan.Autoit
McAfeeTrojan-AitInject.ak
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.34623556
K7GWTrojan ( 00549f261 )
K7AntiVirusTrojan ( 00549f261 )
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
CyrenW32/AutoIt.JD.gen!Eldorado
SymantecPacked.Generic.548
APEXMalicious
AvastAutoIt:Injector-JF [Trj]
ClamAVWin.Malware.Autoit-6985962-0
KasperskyHEUR:Trojan.Win32.Autoit.gen
Ad-AwareTrojan.GenericKD.34623556
SophosMal/AuItInj-A
ComodoTrojWare.Win32.AutoIt.SS@8sg957
F-SecureDropper.DR/AutoIt.Gen8
DrWebTrojan.Inject3.16009
InvinceaML/PE-A + Mal/AuItInj-A
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
EmsisoftTrojan.GenericKD.34623556 (B)
IkarusTrojan.Autoit
AviraDR/AutoIt.Gen8
Antiy-AVLGrayWare/Autoit.ShellCode.a
MicrosoftTrojan:Win32/Wacatac.DC!ml
ArcabitTrojan.Generic.D2105044
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmHEUR:Trojan.Win32.Autoit.gen
GDataTrojan.GenericKD.34623556
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/AutoInj.Exp
Acronissuspicious
VBA32Backdoor.Remcos
ALYacTrojan.GenericKD.34623556
MAXmalware (ai score=88)
MalwarebytesBackdoor.Remcos
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.AutoIt.SS
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
RisingTrojan.Pack-AutoIt!1.BBAC (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Injector.DWD!tr
AVGAutoIt:Injector-JF [Trj]
Cybereasonmalicious.09c69d
Qihoo-360HEUR/QVM10.1.A1A0.Malware.Gen

How to remove AutoIt:Injector-JF [Trj]?

AutoIt:Injector-JF [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment