Trojan

What is “Trojan:Win32/AutoitShellInj.R!MSR”?

Malware Removal

The Trojan:Win32/AutoitShellInj.R!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/AutoitShellInj.R!MSR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the Remcos malware family
  • Creates a copy of itself
  • Creates known Remcos mutexes
  • Creates known Remcos registry keys
  • Anomalous binary characteristics

How to determine Trojan:Win32/AutoitShellInj.R!MSR?


File Info:

name: 1CB42D438E7A2714EF2B.mlw
path: /opt/CAPEv2/storage/binaries/a0bb27674be7dfa180a70fc75716416b2c5b6d716ab513863e01330a4ee25883
crc32: 572DCE9D
md5: 1cb42d438e7a2714ef2b883f2bb14d5c
sha1: 4eae9b113b043fab9532b5f0dd6697d0021aed9c
sha256: a0bb27674be7dfa180a70fc75716416b2c5b6d716ab513863e01330a4ee25883
sha512: ad46bf9340dd4f7eda47df3aed9f6268d20671a4cb6f8147b6aad7509a4e1570e8f29dea2033b820b4b6350be86f1e792f16efb7f9bdcb58fc88a8b78ff7df1b
ssdeep: 24576:QAHnh+eWsN3skA4RV1Hom2KXFmIalKCc9GS5M:Hh+ZkldoPK1XalKCc9nM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T185259C0273D1C036FFAB92739B6AF24156BD79354123852F13982DB9BD701B2263E663
sha3_384: 7780d6a708f4db9c3944ebceadf3eb22afb104955678f35780cadbf99e7a088fa3805795f6b966b606cd2c740b461559
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-05-30 10:20:13

Version Info:

Translation: 0x0809 0x04b0

Trojan:Win32/AutoitShellInj.R!MSR also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.1cb42d438e7a2714
CAT-QuickHealTrojan.AutoIt.AitInject.ZZ
McAfeeArtemis!1CB42D438E7A
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.32026646
K7GWTrojan ( 0054f1021 )
K7AntiVirusTrojan ( 0054f1021 )
CyrenW32/AutoIt.QF.gen!Eldorado
SymantecPacked.Generic.548
ESET-NOD32a variant of Win32/Injector.Autoit.DZK
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Remcos-6985942-1
KasperskyTrojan-Downloader.Win32.AutoIt.aop
AlibabaTrojan:Win32/AutoitU.ali2000008
NANO-AntivirusTrojan.Script.Downloader.iuwddd
MicroWorld-eScanTrojan.GenericKD.32026646
AvastAutoIt:Injector-JF [Trj]
TencentMalware.Win32.Gencirc.10b4d525
Ad-AwareTrojan.GenericKD.32026646
EmsisoftTrojan.GenericKD.32026646 (B)
DrWebTrojan.Packed2.41759
TrendMicroTROJ_GEN.R002C0DKR21
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosML/PE-A + Troj/AutoIt-CMZ
GDataWin32.Backdoor.Remcos.YNTYGG
AviraDR/AutoIt.Gen8
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASCommon.151
ViRobotTrojan.Win32.Z.Autoit.1001272.K
MicrosoftTrojan:Win32/AutoitShellInj.R!MSR
AhnLab-V3Win-Trojan/AutoInj.Exp
VBA32Backdoor.Remcos
ALYacTrojan.GenericKD.32026646
MalwarebytesTrojan.MalPack.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0DKR21
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
IkarusTrojan.Autoit
eGambitUnsafe.AI_Score_95%
FortinetAutoIt/Injector.DZH!tr
BitDefenderThetaAI:Packer.9A3D7CD617
AVGAutoIt:Injector-JF [Trj]
Cybereasonmalicious.38e7a2
PandaTrj/CI.A
MaxSecureWin.MxResIcn.Heur.Gen

How to remove Trojan:Win32/AutoitShellInj.R!MSR?

Trojan:Win32/AutoitShellInj.R!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment