Trojan

What is “Trojan.AutoIT.Injector.AN (B)”?

Malware Removal

The Trojan.AutoIT.Injector.AN (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AutoIT.Injector.AN (B) virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid

How to determine Trojan.AutoIT.Injector.AN (B)?


File Info:

name: 119A34128131E1EBD7DC.mlw
path: /opt/CAPEv2/storage/binaries/6dfdd25ab758e72e890f576c2d55b5356c0bcf84686048ec987e2ac5fac9a66e
crc32: CB88ACC5
md5: 119a34128131e1ebd7dc93ee409ff24a
sha1: 52117ef9cfe3cf1b4ed6230643e2efc6809107d2
sha256: 6dfdd25ab758e72e890f576c2d55b5356c0bcf84686048ec987e2ac5fac9a66e
sha512: d77480fe910f4e5e5900ab87aef6c8d319dceba377f25f9ab7d093c832e1f8dc0d93be32c7330f657b6d7e2c5b9ad21fdf64fc8effb5be042e9a200689d32611
ssdeep: 3072:0JwTek0LZkZGQ8SiiCCry6vdlwwW9quO6lJHXduXUMF+t3wQGoy:0JwTeRw1S6vdnW9NO6JuECQGoy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C9F3BF22B244F0F3D19B22B2AE2DB379A7FE8D3425388987E3584D792951C51E31D783
sha3_384: 159bd021254300919155cb157532b9dd523396b897fc321ff34ef0e836a4c2aeece9a1f9aba0ed019a237901cfccf57b
ep_bytes: 558bec83ec10536a0032dbe86cf0ffff
timestamp: 2013-12-19 00:10:29

Version Info:

0: [No Data]

Trojan.AutoIT.Injector.AN (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AutoIT.Injector.AN
FireEyeGeneric.mg.119a34128131e1eb
CAT-QuickHealTrojan.Necurs.MUE.A3
ALYacTrojan.AutoIT.Injector.AN
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004aea031 )
K7AntiVirusSpyware ( 002891031 )
BaiduWin32.Trojan.Zbot.a
VirITTrojan.Win32.Generic.BFTQ
CyrenW32/Zbot.BR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BZAX
APEXMalicious
ClamAVWin.Spyware.Zbot-1275
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.AutoIT.Injector.AN
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastSf:Crypt-BT [Trj]
TencentTrojan-spy.Win32.Zbot.sbdja
EmsisoftTrojan.AutoIT.Injector.AN (B)
ComodoTrojWare.Win32.Kazy.MKD@4qchol
DrWebTrojan.Proxy.27230
VIPRETrojan-PWS.Win32.Zbot.aac (v)
TrendMicroCryp_Xin1
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
SophosML/PE-A + Mal/Behav-010
IkarusTrojan-Spy.Zbot
AviraTR/Kazy.MK
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Spy.Zbot.DB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R4880
McAfeePWS-Zbot.gen.aov
MalwarebytesMalware.AI.1727413644
TrendMicro-HouseCallCryp_Xin1
RisingStealer.Zbot!1.648A (RDMK:cmRtazq2hDNd85zoqve/KpyOAtzR)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AAU!tr
BitDefenderThetaGen:NN.ZexaF.34182.jmW@a4d3lkp
AVGSf:Crypt-BT [Trj]
Cybereasonmalicious.28131e
PandaTrj/Genetic.gen

How to remove Trojan.AutoIT.Injector.AN (B)?

Trojan.AutoIT.Injector.AN (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment