Trojan

Trojan:Win32/AutoitInject.BH!rfn removal guide

Malware Removal

The Trojan:Win32/AutoitInject.BH!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/AutoitInject.BH!rfn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
checkip.amazonaws.com

How to determine Trojan:Win32/AutoitInject.BH!rfn?


File Info:

crc32: 688BB36A
md5: 8f28f202ea7aa121b46e89dc91f163ef
name: revc.exe
sha1: 060161ab2efd071ef754317e6ec2a31fa5a8f0a9
sha256: c8872df5a52cfef6a38f1197898666f9c59285807f1b6407cfc8e67304a3c10c
sha512: c5fde545e7e2a2360d096e64618f469792796fbfd50f8d752045464fc9535d3f0d5e80883a495118d0bf7a735139ab1149f0e95a8f1da4673c3abae651185f8c
ssdeep: 24576:MAHnh+eWsN3skA4RV1Hom2KXMmHaWAYmH+o1Ao0rGxJC9DTIHZC5:rh+ZkldoPK8Ya3Ys+oJFxJCeH+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan:Win32/AutoitInject.BH!rfn also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.32428301
FireEyeGeneric.mg.8f28f202ea7aa121
CAT-QuickHealTrojan.AutoIt.Injector.ZZ
ALYacSpyware.AgentTesla
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005577711 )
BitDefenderTrojan.GenericKD.32428301
K7GWTrojan ( 005577711 )
Invinceaheuristic
F-ProtW32/Autoit.G.gen!Eldorado
SymantecInfostealer
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.32428301
KasperskyTrojan.Win32.Bsymem.lkl
AlibabaTrojan:Win32/Bsymem.c83198c4
NANO-AntivirusTrojan.Win32.Bsymem.fyvcxc
ViRobotTrojan.Win32.S.Agent.1293312.H
RisingTrojan.Injector/Autoit!1.BB82 (CLASSIC)
Ad-AwareTrojan.GenericKD.32428301
SophosTroj/Bladab-AD
ComodoMalware@#1e4sne4r8rs34
F-SecureDropper.DR/AutoIt.Gen8
DrWebTrojan.PWS.Stealer.26962
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.AGENTTESLA.THIAHAI
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftTrojan.GenericKD.32428301 (B)
IkarusTrojan.Autoit
CyrenW32/Autoit.G.gen!Eldorado
WebrootW32.Trojan.Gen
AviraDR/AutoIt.Gen8
eGambitUnsafe.AI_Score_99%
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1EED10D
AegisLabHacktool.Win32.Gamehack.3!e
ZoneAlarmTrojan.Win32.Bsymem.lkl
MicrosoftTrojan:Win32/AutoitInject.BH!rfn
AhnLab-V3Win-Trojan/Autoinj02.Exp
McAfeeArtemis!8F28F202EA7A
VBA32Trojan.Bsymem
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.EGY
TrendMicro-HouseCallTrojanSpy.Win32.AGENTTESLA.THIAHAI
TencentWin32.Trojan.Bsymem.Ecaq
MaxSecureTrojan.Malware.74552811.susgen
FortinetAutoIt/Injector.EIE!tr
BitDefenderThetaAI:Packer.FFA318C715
AVGAutoIt:Dropper-DL [Trj]
AvastAutoIt:Dropper-DL [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.97b

How to remove Trojan:Win32/AutoitInject.BH!rfn?

Trojan:Win32/AutoitInject.BH!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment