Trojan

Trojan.AutoIt.AitInject.ZZ removal

Malware Removal

The Trojan.AutoIt.AitInject.ZZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AutoIt.AitInject.ZZ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
0x21.in

How to determine Trojan.AutoIt.AitInject.ZZ?


File Info:

crc32: 077F9794
md5: e2ac2c69eb9b216fdc465e8c2b0544e0
name: E2AC2C69EB9B216FDC465E8C2B0544E0.mlw
sha1: 0c4150420e5ddc8ce559fde018f3cd49dd359c35
sha256: 4ce95594d4b615d8612589de57a0df0dfc3d059f0bc61f7df4d2bbeefe5323e4
sha512: 2780229e4ecddf5b9ac3c70e7c6a62c28d4a0f7a918b577f46ac8459a01acada9d14cda3ae1e61123961a835c5a110f73c517029a42b6dccc0a86bea54dff155
ssdeep: 24576:fptBabhF7/ef7PzcXjlVsV9FaI1IXgM6YmenKKSUlmDaGJTA4Pqa6jUvOkQwKYW7:Ja/LeDr4jlVsjFap5aLKLkDl+dUvO9YG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2018 Adobe Incorporated. All rights reserved.
FileVersion: ...
CompanyName: Adobe Systems Incorporated
ProductName: Adobe Download Manager
ProductVersion: ...
FileDescription: Adobe Download Manager
OriginalFilename: Adobe Download Manager
Translation: 0x0409 0x04b0

Trojan.AutoIt.AitInject.ZZ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.525018
FireEyeGeneric.mg.e2ac2c69eb9b216f
CAT-QuickHealTrojan.AutoIt.AitInject.ZZ
McAfeeArtemis!E2AC2C69EB9B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Variant.Ursu.525018
K7GWTrojan ( 700000111 )
Cybereasonmalicious.9eb9b2
TrendMicroTSPY_TINCLEX.SM1
BitDefenderThetaGen:NN.ZexaF.34634.zqW@auVdLFh
CyrenW32/FakeDoc.N.gen!Eldorado
SymantecPacked.Generic.548
ESET-NOD32a variant of Win32/Packed.AutoIt.OM
APEXMalicious
ClamAVWin.Malware.Generic-6623004-0
KasperskyHEUR:Trojan.Win32.Pincav.gen
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Quasar.foekoa
RisingBackdoor.Quasar!1.B1DD (CLASSIC)
Ad-AwareGen:Variant.Ursu.525018
SophosMal/Hvnc-A
ComodoBackdoor.Win32.QuasarRAT.A@8m6u7h
F-SecureTrojan.TR/AD.Xiclog.nmpoi
DrWebBackDoor.HVNC.15
InvinceaML/PE-A + Mal/AuItInj-A
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
EmsisoftGen:Variant.Ursu.525018 (B)
AviraTR/Hijacker.W
MAXmalware (ai score=100)
Antiy-AVLGrayWare/Autoit.ShellCode.a
MicrosoftVirTool:Win32/AutInject
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Ursu.D802DA
AhnLab-V3Win-Trojan/AutoInj.Exp
ZoneAlarmHEUR:Trojan.Win32.Pincav.gen
GDataGen:Variant.Ursu.525018
CynetMalicious (score: 100)
VBA32BScope.Trojan.Invader
ALYacGen:Variant.Ursu.525018
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/Genetic.gen
ZonerTrojan.Win32.82233
TrendMicro-HouseCallTSPY_TINCLEX.SM1
TencentMalware.Win32.Gencirc.10b0d056
YandexTrojan.GenAsa!eJ2W40k2TSg
IkarusBackdoor.Win32.Hupigon
eGambitTrojan.Generic
FortinetW32/Carberp.BU!tr.dldr
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM20.1.40A0.Malware.Gen

How to remove Trojan.AutoIt.AitInject.ZZ?

Trojan.AutoIt.AitInject.ZZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment