Malware

Win32/Injector.Autoit.CSK removal tips

Malware Removal

The Win32/Injector.Autoit.CSK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.CSK virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Harvests cookies for information gathering
  • Creates known XtremeRAT mutexes
  • Anomalous binary characteristics

How to determine Win32/Injector.Autoit.CSK?


File Info:

name: E1430A4E62684851C623.mlw
path: /opt/CAPEv2/storage/binaries/3eaf7501156e46093b38bf7520ef00eb04eaabe210d9942bc391ba30f0bf1389
crc32: 78E57F42
md5: e1430a4e62684851c6230d0661784689
sha1: fe9d98e762f7d09f3dd1bf74c11bd5933bbd5219
sha256: 3eaf7501156e46093b38bf7520ef00eb04eaabe210d9942bc391ba30f0bf1389
sha512: 63e23a6f0676dded93ccb350bdc43bd03387b7d4633e6430f9c24cbaa902a5d253c5c0a07fc43eca68fc8c8265462380ae912629bb854997c9f965d4edf30a98
ssdeep: 24576:V4lavt0LkLL9IMixoEgeanarcAA0fNq9MmCS:skwkn9IMHeann0laPCS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F25BE0373DD83A1C3729173BA66BB41AEBB7C2505A1F49B2FD5093DF920162921E673
sha3_384: 8200027cbe662c9455c357de4a2f7048d1f35d458e106d4486a2adf4942d191d6950157d70f15a49251a1bc6d12be517
ep_bytes: e897cf0000e97ffeffffcccccccccccc
timestamp: 2017-02-15 22:55:10

Version Info:

Translation: 0x0809 0x04b0

Win32/Injector.Autoit.CSK also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Xtrat.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.4439447
ClamAVWin.Trojan.Agent-6505547-0
McAfeeArtemis!E1430A4E6268
CylanceUnsafe
VIPRETrojan.GenericKD.4439447
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005053b71 )
AlibabaTrojan:Win32/Xtrat.1191aa97
K7GWTrojan ( 005053b71 )
Cybereasonmalicious.e62684
CyrenW32/Backdoor.SFXW-3216
SymantecTrojan.Gen.2
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.Autoit.CSK
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Xtrat.aafd
BitDefenderTrojan.GenericKD.4439447
NANO-AntivirusTrojan.Win32.Nanocore.elsbpk
AvastAutoIt:Agent-ANW [Trj]
TencentWin32.Trojan.Xtrat.Rgil
Ad-AwareTrojan.GenericKD.4439447
SophosTroj/AutoIt-BWS
DrWebTrojan.Nanocore.16
TrendMicroBKDR_XTRAT.AUSK
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e1430a4e62684851
EmsisoftTrojan.GenericKD.4439447 (B)
GDataTrojan.GenericKD.4439447
AviraDR/AutoIt.Gen8
ArcabitTrojan.Generic.D43BD97
MicrosoftBackdoor:Win32/Xtrat.AC
GoogleDetected
AhnLab-V3Trojan/Win32.Xtrat.C3990820
ALYacTrojan.GenericKD.4439447
MAXmalware (ai score=100)
VBA32Trojan.Xtrat
MalwarebytesBackdoor.Bladabindi
TrendMicro-HouseCallBKDR_XTRAT.AUSK
IkarusTrojan.Win32.Tiny
FortinetW32/Injector.CRT!tr
BitDefenderThetaAI:Packer.A158364F15
AVGAutoIt:Agent-ANW [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.Autoit.CSK?

Win32/Injector.Autoit.CSK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment