Trojan

How to remove “Trojan.AutoIT.Injector.A”?

Malware Removal

The Trojan.AutoIT.Injector.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AutoIT.Injector.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristics of BlackRemote/BlackRAT RAT
  • Attempts to bypass application whitelisting by executing .NET utility in a suspended state, potentially for injection
  • CAPE detected the njRat malware family
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Trojan.AutoIT.Injector.A?


File Info:

name: 6BA7101C2E1408A7AAFE.mlw
path: /opt/CAPEv2/storage/binaries/3654fcba1350a716f5348b19a880ebe4b40168c40e027d9766f39e9dd86c533b
crc32: 82D0402C
md5: 6ba7101c2e1408a7aafe870aab2d76d2
sha1: 413ca5dd66267b3c4babf36f3212f2cfdce211a7
sha256: 3654fcba1350a716f5348b19a880ebe4b40168c40e027d9766f39e9dd86c533b
sha512: 676283a3918c2be70d2cb519c6a250a5e90315664539df1c699758b0afa898cb8088447264eb179dd70f8c2bc46d53688ff4e1cecab4efbe717c656b2eff4a8b
ssdeep: 12288:WquErHF6xC9D6DmR1J98w4oknqO/CyQftQYqYbLmKc:brl6kD68JmlokQfttqY2Kc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1169412829BFA9216F6F61F35483898B44A35BC57AE38C64D86247C4F7C31B04DDA4B72
sha3_384: f963a1cf58654b4d48949b0e9f3309714200090afc958e900b8fcc18961bb9b01a1f5a030367a17dd094a36192760530
ep_bytes: 60be004049008dbe00d0f6ff57eb0b90
timestamp: 2019-05-14 14:55:21

Version Info:

Translation: 0x0809 0x04b0

Trojan.AutoIT.Injector.A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.AutoIt.426
MicroWorld-eScanTrojan.GenericKD.33615682
FireEyeGeneric.mg.6ba7101c2e1408a7
CAT-QuickHealTrojan.AutoIT.Injector.A
McAfeeArtemis!6BA7101C2E14
CylanceUnsafe
ZillyaTrojan.Packed.Win32.160071
K7AntiVirusTrojan ( 0054e3651 )
K7GWTrojan ( 0054e3651 )
Cybereasonmalicious.c2e140
BitDefenderThetaAI:Packer.04BE515817
CyrenW32/AutoIt.QF.gen!Eldorado
SymantecAUT.Heuristic!gen5
ESET-NOD32a variant of Win32/Packed.AutoIt.QS
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
ClamAVWin.Malware.Azorult-6971822-0
KasperskyHEUR:Trojan.Win32.AutoIt.gen
BitDefenderTrojan.GenericKD.33615682
NANO-AntivirusTrojan.Win32.AutoIt.jiqnwh
AvastAutoIt:Injector-JF [Trj]
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
Ad-AwareTrojan.GenericKD.33615682
SophosML/PE-A + Troj/AutoIt-CLG
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.gc
EmsisoftTrojan.GenericKD.33615682 (B)
IkarusTrojan.Autoit
AviraDR/AutoIt.Gen8
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASCommon.151
MicrosoftTrojan:Win32/AutoitInject.BH!MTB
GDataTrojan.GenericKD.33615682
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C3244818
VBA32Backdoor.MSIL.Bladabindi
ALYacTrojan.GenericKD.33615682
MalwarebytesTrojan.MalPack.Generic
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Injector.ESJ!tr
AVGAutoIt:Injector-JF [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.AutoIT.Injector.A?

Trojan.AutoIT.Injector.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment