Trojan

How to remove “Trojan:Win32/AutoitInject.JNAA!MTB”?

Malware Removal

The Trojan:Win32/AutoitInject.JNAA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/AutoitInject.JNAA!MTB virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Anomalous binary characteristics

How to determine Trojan:Win32/AutoitInject.JNAA!MTB?


File Info:

name: 1FBA4189543010612417.mlw
path: /opt/CAPEv2/storage/binaries/4fe520964b0c84c62b6274217ad292cb2fb80fa49c1435b14194d8e40c9a633c
crc32: 4181ADBB
md5: 1fba4189543010612417c328090ade8e
sha1: e19fbe34aa03eaa523d05db0e1384e71f2b69413
sha256: 4fe520964b0c84c62b6274217ad292cb2fb80fa49c1435b14194d8e40c9a633c
sha512: d6aa287ba22029060a7243caaf7129eb2a803cabff7dd13942b08b92422d83374e22216d6428403a9767a52dae4cc74ba0154144a4486e1d9d0524a8ca8348f1
ssdeep: 49152:wVg5tQ7aBTgb8z70u634H18SNDTuqJh0tFNgc4Wph:Sg56c9Ag8GvhGx4WL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196A5F12233EE8361C7725273BE657702BE7B7C6906B5F56B2FD40D3CA920121524E6A3
sha3_384: f105dfcee4223c6f71842895fb0d29dad652847c2b86e038e213e3e6f843b0091472a899fb35d2679dff6163e1725c3c
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2021-10-26 02:29:38

Version Info:

0: [No Data]

Trojan:Win32/AutoitInject.JNAA!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
SkyhighBehavesLike.Win32.PUPXVW.vc
McAfeeArtemis!1FBA41895430
MalwarebytesGeneric.Malware.AI.DDS
CrowdStrikewin/malicious_confidence_100% (W)
tehtrisGeneric.Malware
CynetMalicious (score: 100)
APEXMalicious
SophosMal/Generic-S
IkarusTrojan.Win32.AutoitInject
Kingsoftmalware.kb.a.955
MicrosoftTrojan:Win32/AutoitInject.JNAA!MTB
GoogleDetected
VBA32Trojan.Autoit.F
TrendMicro-HouseCallTROJ_GEN.R002H06CO24
FortinetPossibleThreat.PALLAS.M
DeepInstinctMALICIOUS

How to remove Trojan:Win32/AutoitInject.JNAA!MTB?

Trojan:Win32/AutoitInject.JNAA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment