Trojan

Trojan:Win32/Autoitinjector.S!ibt removal guide

Malware Removal

The Trojan:Win32/Autoitinjector.S!ibt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Autoitinjector.S!ibt virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Attempts to identify installed AV products by installation directory
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Autoitinjector.S!ibt?


File Info:

name: FD04D2A29E438EDE4CD0.mlw
path: /opt/CAPEv2/storage/binaries/897bfae811cd3a6bbbd3cf77f21cdd0cd21dd5a5077f4266c931205bc2477fdd
crc32: 906888A7
md5: fd04d2a29e438ede4cd012b258d5c4fa
sha1: f4618c43933d6ea6d889ee7105b7aa5aa48883b0
sha256: 897bfae811cd3a6bbbd3cf77f21cdd0cd21dd5a5077f4266c931205bc2477fdd
sha512: 7a5a323d17d5cc61b760492a2959abe50cdedc6ede7320a0dd0fb2ff19f48d5187eb3763567fa4316a000f1aec49f78c6b0edff4fec97477d02fd9e8819e42ce
ssdeep: 6144:kof7DeNUSfGgHCU/2McdfoI/ZX0rYfCzuCCMQZN/OdnFQ8+PHPF53ljgIJ2jXzyf:PYV6MorX7qzuC3QHO9FQVHPF51jgcNQu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E8412C01ED2D97AC0A523BAC43BCD10A4217871CAD53B698799F22EF835783E85756F
sha3_384: cf7bcbc1ea85fb058ab9b49cc5ae76f02b4c12d0ba3016052c500ca1be9e1cdc85e19feb71a288cafa882235f50695e5
ep_bytes: 60be00b048008dbe0060f7ff57eb0b90
timestamp: 2019-05-29 18:17:16

Version Info:

FileVersion: 3.3.14.5
Comments: http://www.autoitscript.com/autoit3/
FileDescription: NT Kernel & System
ProductVersion: 3.3.14.5
LegalCopyright: ©1999-2018 Jonathan Bennett & AutoIt Team
Translation: 0x0809 0x04b0

Trojan:Win32/Autoitinjector.S!ibt also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Autoit.b!c
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDropper:Win32/CoinMiner.2ed10c41
K7GWRiskware ( 0040eff71 )
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Autoit-9817465-0
KasperskyHEUR:Trojan-Dropper.Win32.Autoit.gen
SophosMal/Generic-R
DrWebTrojan.AutoIt.289
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
WebrootW32.Rogue.Gen
GridinsoftRansom.Win32.Miner.sa
MicrosoftTrojan:Win32/Autoitinjector.S!ibt
CynetMalicious (score: 100)
McAfeeArtemis!FD04D2A29E43
MalwarebytesRiskWare.BitCoinMiner
TrendMicro-HouseCallTROJ_GEN.R002H01LR21
IkarusTrojan.Win32.Autoitinjector
eGambitUnsafe.AI_Score_60%
FortinetW32/PossibleThreat
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/Autoitinjector.S!ibt?

Trojan:Win32/Autoitinjector.S!ibt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment