Trojan

Trojan.Injector.AutoIt removal guide

Malware Removal

The Trojan.Injector.AutoIt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Injector.AutoIt virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Trojan.Injector.AutoIt?


File Info:

crc32: 4974253F
md5: 5f3889b0fe910a619d44526ac54fc09f
name: rvcbxbvcd.exe
sha1: 31ff7f3d53181fa7b0b926deb3a41d290d45b8c1
sha256: 58f8dc29fa54f6928c5627e0b712c5cff209413d8de8bfeabcfc1bbaddb3a7a7
sha512: f43cb84bc3c05131b12ae0ce662e4f0dd7c7aa49ccdf0da090edcd28fb7694452c0028c5e1f534c46375d32f92b71f329013342b6953acd5096e993858ce4b25
ssdeep: 24576:Gu6J33O0c+JY5UZ+XC0kGso6FaDcut1rdd31nPWY:Iu0c++OCvkGs9FaDN731+Y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan.Injector.AutoIt also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Variant.Strictor.228565
FireEyeGen:Variant.Strictor.228565
Qihoo-360Win32/Backdoor.bb9
McAfeeArtemis!5F3889B0FE91
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0055e2ce1 )
BitDefenderGen:Variant.Strictor.228565
K7GWTrojan ( 0055e2ce1 )
BitDefenderThetaGen:NN.ZexaF.33558.@uW@aGLYx3ci
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Strictor.228565
KasperskyBackdoor.Win32.Androm.tqpp
RisingTrojan.Obfus/Autoit!1.C07A (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Strictor.228565 (B)
F-SecureHeuristic.HEUR/AGEN.1039730
McAfee-GW-EditionBehavesLike.Win32.Downloader.fh
Trapminemalicious.high.ml.score
SophosMal/Generic-S
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1039730
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Strictor.D37CD5
ZoneAlarmBackdoor.Win32.Androm.tqpp
AhnLab-V3Win-Trojan/Autoinj05.Exp
ALYacTrojan.Ransom.Crysis
Ad-AwareGen:Variant.Strictor.228565
MalwarebytesTrojan.Injector.AutoIt
ESET-NOD32a variant of Generik.FWECIZR
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.Injector.AutoIt?

Trojan.Injector.AutoIt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment