Malware

Should I remove “VirTool:Win32/AutInject”?

Malware Removal

The VirTool:Win32/AutInject is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/AutInject virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • At least one process apparently crashed during execution
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

0x21.in

How to determine VirTool:Win32/AutInject?


File Info:

crc32: BB6A4CFC
md5: 3accaf0d4ab64c6864ab639ada3f67f3
name: 3ACCAF0D4AB64C6864AB639ADA3F67F3.mlw
sha1: 895dd4a2559801a43dc324015cfd63cfbc287a40
sha256: 4839f576da58bcfd097c24c5c3ff4d72029377dfd450420e99b745b3deda62bc
sha512: f77c5ff17ee8a8213fc9eb87aeed2563f636f326d3bf90d0fe77cfbe34f27bae0e36d2ffcea8a64345136958b8197620c50eacabdb00e4ade30f4c272ac67259
ssdeep: 49152:6MHI3YSzDMB8WHFap5aLKLkDl+dUvO9YB:3I9nMBlHwa+p39M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2018 Adobe Incorporated. All rights reserved.
FileVersion: ...
CompanyName: Adobe Systems Incorporated
ProductName: Adobe Download Manager
ProductVersion: ...
FileDescription: Adobe Download Manager
OriginalFilename: Adobe Download Manager
Translation: 0x0409 0x04b0

VirTool:Win32/AutInject also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.HVNC.15
MicroWorld-eScanGen:Variant.Ursu.525018
FireEyeGeneric.mg.3accaf0d4ab64c68
CAT-QuickHealTrojan.AutoIt.AitInject.ZZ
ALYacGen:Variant.Ursu.525018
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Variant.Ursu.525018
K7GWTrojan ( 700000111 )
Cybereasonmalicious.d4ab64
TrendMicroTSPY_TINCLEX.SM1
BitDefenderThetaGen:NN.ZexaF.34590.zqW@auVdLFh
CyrenW32/FakeDoc.N.gen!Eldorado
SymantecPacked.Generic.548
ZonerTrojan.Win32.82233
TrendMicro-HouseCallTSPY_TINCLEX.SM1
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Generic-6623004-0
KasperskyHEUR:Trojan.Win32.Pincav.gen
NANO-AntivirusTrojan.Win32.Quasar.foekoa
TencentMalware.Win32.Gencirc.10b0d056
Ad-AwareGen:Variant.Ursu.525018
SophosMal/Hvnc-A
ComodoBackdoor.Win32.QuasarRAT.A@8m6u7h
F-SecureTrojan.TR/AD.Xiclog.nmpoi
InvinceaML/PE-A + Mal/AuItInj-A
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
EmsisoftGen:Variant.Ursu.525018 (B)
IkarusBackdoor.Win32.Hupigon
AviraTR/Hijacker.W
Antiy-AVLGrayWare/Autoit.ShellCode.a
MicrosoftVirTool:Win32/AutInject
ArcabitTrojan.Ursu.D802DA
ZoneAlarmHEUR:Trojan.Win32.Pincav.gen
GDataGen:Variant.Ursu.525018
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/AutoInj.Exp
Acronissuspicious
McAfeeArtemis!3ACCAF0D4AB6
MAXmalware (ai score=86)
VBA32BScope.Trojan.Invader
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/Packed.AutoIt.OM
RisingBackdoor.Quasar!1.B1DD (CLASSIC)
YandexTrojan.GenAsa!eJ2W40k2TSg
eGambitTrojan.Generic
FortinetW32/Carberp.BU!tr.dldr
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM41.1.3967.Malware.Gen

How to remove VirTool:Win32/AutInject?

VirTool:Win32/AutInject removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment