Malware

VirTool:Win32/AutInject.A (file analysis)

Malware Removal

The VirTool:Win32/AutInject.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/AutInject.A virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Attempts to disable UAC

Related domains:

hackerboy.no-ip.org

How to determine VirTool:Win32/AutInject.A?


File Info:

crc32: 2A3F9B9E
md5: c48e133293ff856468ff9883462beaf2
name: C48E133293FF856468FF9883462BEAF2.mlw
sha1: 711cdafecb9ee95aab4f7f392bcfb274ab2bb07e
sha256: dce2689e68c444a01fa540fedf3d6c4f2420473b48a9de26feea7375b8133b17
sha512: 8ef15e0a8c31a4b96231b858d82fdfc1502bd5ac0a35dd24fa846bbfb5865b728e2d20b9d99683310b7984b232a4d5d772932c2c6d3de8691c3f9298e6defc37
ssdeep: 12288:kBMmKGnhDT+JlCTXMjY3FhuPJT1uxp62KW8CcCzyU56RZv+0a2J/rq2iWPD:mMmnDC+TdFhuPJEv8W8CcQy2U1UzF0
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

CompiledScript: AutoIt v3 Script : 3, 3, 0, 0
FileVersion: 3, 3, 0, 0
FileDescription:
Translation: 0x0809 0x04b0

VirTool:Win32/AutInject.A also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.11738031
FireEyeTrojan.Generic.11738031
Qihoo-360HEUR/Malware.QVM01.Gen
McAfeeArtemis!C48E133293FF
CylanceUnsafe
VIPREBackdoor.Win32.Turkojan.hpe (v)
SangforMalware
BitDefenderTrojan.Generic.11738031
Cybereasonmalicious.293ff8
BaiduWin32.Trojan.Injector.ij
CyrenW32/A-b245bea5!Eldorado
SymantecBackdoor.Turkojan
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Autoit-156
KasperskyTrojan.Win32.Autoit.anv
NANO-AntivirusTrojan.Script.Agent.debxaj
Ad-AwareTrojan.Generic.11738031
EmsisoftTrojan.Generic.11738031 (B)
ComodoMalware@#1unbqth44m7kf
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.58022
ZillyaBackdoor.Turkojan.Win32.7526
McAfee-GW-EditionBehavesLike.Win32.Spyware.bc
SophosW32/AutoIt-OK
IkarusTrojan.AutoIT.Injector
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
MicrosoftVirTool:Win32/AutInject.A
ArcabitTrojan.Generic.DB31BAF
ZoneAlarmTrojan.Win32.Autoit.anv
GDataTrojan.Generic.11738031
CynetMalicious (score: 85)
BitDefenderThetaAI:Packer.C7FE32A316
ALYacTrojan.Generic.11738031
VBA32Trojan.Autoit.Injcrypt
MalwarebytesMalware.AI.1909999789
PandaTrj/Autoit.gen
ESET-NOD32multiple detections
TencentWin32.Trojan.Autoit.Sxyc
eGambitUnsafe.AI_Score_87%
FortinetW32/Fynloski.AM!tr
AVGAutoIt:Agent-AW [Trj]
AvastAutoIt:Agent-AW [Trj]

How to remove VirTool:Win32/AutInject.A?

VirTool:Win32/AutInject.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment