Trojan

Trojan:Win32/AutoitInject.PDS!MTB removal instruction

Malware Removal

The Trojan:Win32/AutoitInject.PDS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/AutoitInject.PDS!MTB virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
pomf.lain.la

How to determine Trojan:Win32/AutoitInject.PDS!MTB?


File Info:

crc32: 1D4A5738
md5: 48af9b094ed8a656a1d63091cc022ae0
name: 48AF9B094ED8A656A1D63091CC022AE0.mlw
sha1: b901d8ea854b1d9045863a8c2232ba4d4bbdd241
sha256: bf70a83b41c0e405e4c21c3253d0a80a34e08a2da16ad6e36e77d2f070cb6f82
sha512: abbf86a39dc5f76eb5bd3c2169dff6fe1a39dc40655f4b15a536e7ed474dc6a87fdd3adf6cc3ebac535a61eb3dfac0f1f576e1a83288102019d92b160150abe2
ssdeep: 12288:jXe9PPlowWX0t6mOQwg1Qd15CcYk0We1MY94thdm5Fo:KhloDX0XOf4+tzgO
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

Trojan:Win32/AutoitInject.PDS!MTB also known as:

LionicTrojan.MSIL.Agensla.i!c
Elasticmalicious (high confidence)
ALYacAIT:Trojan.Nymeria.4914
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan-Downloader ( 00581a261 )
K7AntiVirusTrojan-Downloader ( 00581a261 )
CyrenW32/Autoit.NHRW-8280
SymantecTrojan Horse
ESET-NOD32Win32/TrojanDownloader.Autoit.PET
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-PSW.MSIL.Agensla.vdg
BitDefenderTrojan.GenericKD.37513522
MicroWorld-eScanTrojan.GenericKD.37513522
Ad-AwareTrojan.GenericKD.37513522
SophosMal/Generic-S + Troj/Tesla-QR
ComodoMalware@#2x559fr8irysk
F-SecureTrojan.TR/Dldr.Autoit.gzfzn
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.bc
FireEyeGeneric.mg.48af9b094ed8a656
EmsisoftTrojan.GenericKD.37513522 (B)
WebrootW32.Trojan.FL
AviraTR/Dldr.Autoit.gzfzn
eGambitUnsafe.AI_Score_99%
KingsoftWin32.PSWTroj.Agensla.v.(kcloud)
MicrosoftTrojan:Win32/AutoitInject.PDS!MTB
ArcabitTrojan.Generic.D23C6932
ZoneAlarmTrojan-PSW.MSIL.Agensla.vdg
GDataTrojan.GenericKD.37513522
AhnLab-V3Malware/Win.Generic.C4620407
McAfeeArtemis!48AF9B094ED8
MAXmalware (ai score=84)
VBA32TrojanPSW.MSIL.Agensla
MalwarebytesMalware.AI.2867527536
PandaTrj/CI.A
YandexTrojan.Igent.bWvgJc.4
IkarusTrojan.Autoit
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Injector.BFC6!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/AutoitInject.PDS!MTB?

Trojan:Win32/AutoitInject.PDS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment