Trojan

How to remove “Trojan:Win32/AutoitInject.RE!MTB”?

Malware Removal

The Trojan:Win32/AutoitInject.RE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/AutoitInject.RE!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Azorult malware family
  • Binary file triggered YARA rule
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/AutoitInject.RE!MTB?


File Info:

name: 6CAC8B43A0DCA562FF41.mlw
path: /opt/CAPEv2/storage/binaries/d36ee8366e810b46b756b6eb4d2a344996aefe87c1e297af3046a179296ff06d
crc32: DA6D48B8
md5: 6cac8b43a0dca562ff41026d8edfe11d
sha1: fc6181cbc4b3f16afef037117b6178c543ba137f
sha256: d36ee8366e810b46b756b6eb4d2a344996aefe87c1e297af3046a179296ff06d
sha512: bbff539438472048ba14c25c3e52f59e1457bd540bef9194a6996bd13d82d649103c401dbde0061d7228aec8e6a883747a33928298463211f534cfef77d35201
ssdeep: 24576:ju6J33O0c+JY5UZ+XC0kGsoTac255vkq99WYL:tu0c++OCvkGsEac2zcYL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE45AE12B3CD8360CE675633BF2A7B112E7B7C651A30F45B1E883D796B721A1122D663
sha3_384: 69f9db1150ff73d254226dfe52d5691a0032fe9fb1c287a527b58bf93961d2bbc12897825ef7925f03ae028039d4c2ab
ep_bytes: e8b5d00000e97ffeffffcccccccccccc
timestamp: 2019-05-15 07:59:40

Version Info:

Translation: 0x0809 0x04b0

Trojan:Win32/AutoitInject.RE!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.AutoIt.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.AutoIt.Agent.VQ
FireEyeGeneric.mg.6cac8b43a0dca562
CAT-QuickHealTrojan.AutoIT.Injector.A
SkyhighBehavesLike.Win32.TrojanAitInject.th
McAfeeArtemis!6CAC8B43A0DC
Cylanceunsafe
SangforVirus.Win32.Save.a
AlibabaTrojan:Win32/AutoitCrypt.180
K7GWTrojan ( 0055dc781 )
K7AntiVirusTrojan ( 0055dc781 )
BitDefenderThetaAI:Packer.39DE3CF819
VirITTrojan.Win32.AutoIt_Heur.A
SymantecAUT.Heuristic!gen5
tehtrisGeneric.Malware
ESET-NOD32Win32/Packed.Autoit.NBC suspicious
APEXMalicious
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
Paloaltogeneric.ml
ClamAVWin.Malware.Autoit-10018187-0
KasperskyUDS:Trojan.Win32.Autoit.gen
BitDefenderTrojan.AutoIt.Agent.VQ
AvastAutoIt:Injector-JF [Trj]
TencentWin32.Trojan.Autoit.Timw
EmsisoftTrojan.AutoIt.Agent.VQ (B)
F-SecureDropper.DR/AutoIt.Gen8
DrWebTrojan.AutoIt.452
VIPRETrojan.AutoIt.Agent.VQ
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
Trapminemalicious.high.ml.score
SophosTroj/AutoIt-CLG
IkarusTrojan.Win32.Autoit
GoogleDetected
AviraDR/AutoIt.Gen8
VaristW32/AutoIt.QF.gen!Eldorado
Antiy-AVLTrojan[Packed]/Win32.Autoit
KingsoftWin32.Trojan.Autoit.gen
MicrosoftTrojan:Win32/AutoitInject.RE!MTB
ArcabitTrojan.AutoIt.Agent.VQ
ViRobotTrojan.Win.Z.Autoit.1202272.B
ZoneAlarmUDS:Trojan.Win32.Autoit.gen
GDataTrojan.AutoIt.Agent.VQ
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/AutoInj.Exp
ALYacTrojan.AutoIt.Agent.VQ
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
FortinetAutoIt/Injector.ESJ!tr
AVGAutoIt:Injector-JF [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/AutoitInject.RA8PHU

How to remove Trojan:Win32/AutoitInject.RE!MTB?

Trojan:Win32/AutoitInject.RE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment