Malware

Win32/Injector.Autoit.DAA malicious file

Malware Removal

The Win32/Injector.Autoit.DAA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.DAA virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Injector.Autoit.DAA?


File Info:

crc32: 00FC8736
md5: 019f50264a6dce7aa742e336e7a59b0d
name: tmpbw21tn4k
sha1: dd37e18c2f72a4e2494997e88c4ebb3781d57e53
sha256: 291dadb4e68598e4ac8e213d24022da34fc3c50e690b9578f9769c807a9649ce
sha512: c9f39e480e4a3db99732089a76526e2df84693652ae9ace7fde5d995bdfed934be06977e26bbb174106468fbf4afd933b6e86fc8850e3f599cd84d7adc0aaa58
ssdeep: 24576:uRmJkcoQricOIQxiZY1iaCTPbguA0oyNeZiP4AbZ6NWIyA0JRrVWW:7JZoQrbTFZY1iaCTP8j0oyIZY4NWIyAu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Win32/Injector.Autoit.DAA also known as:

BkavW32.DropperZbotS.Trojan
DrWebTrojan.PWS.Banker1.14562
MicroWorld-eScanTrojan.GenericKD.34062945
FireEyeGeneric.mg.019f50264a6dce7a
CAT-QuickHealBackdoor.AutoIt.Fynloski.OC
McAfeeArtemis!019F50264A6D
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderTrojan.GenericKD.34062945
K7GWTrojan ( 700000111 )
Cybereasonmalicious.64a6dc
Invinceaheuristic
BitDefenderThetaAI:Packer.CF65E5A615
F-ProtW32/AutoIt.AQ.gen!Eldorado
SymantecTrojan.Gen.MBT
AvastWin32:GenMalicious-TK [Trj]
GDataTrojan.GenericKD.34062945
KasperskyTrojan.Win32.Autoit.dxi
NANO-AntivirusTrojan.Script.Agent.debxaj
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.34062945 (B)
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.AutoIT.Win32.41776
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
Trapminemalicious.moderate.ml.score
SophosTroj/Malit-FE
IkarusPacker.Win32.Krap
CyrenW32/AutoIt.AQ.gen!Eldorado
MaxSecureTrojan.Autoit.AZA
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Generic.D207C261
SUPERAntiSpywareTrojan.Agent/Gen-Undef
ZoneAlarmTrojan.Win32.Autoit.dxi
CynetMalicious (score: 100)
VBA32BScope.Trojan.Toga
ALYacAIT:Trojan.Autoit.CNI
MAXmalware (ai score=81)
Ad-AwareTrojan.GenericKD.34062945
APEXMalicious
ESET-NOD32a variant of Win32/Injector.Autoit.DAA
eGambitUnsafe.AI_Score_93%
FortinetW32/Fynloski.AM!tr
AVGWin32:GenMalicious-TK [Trj]
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360HEUR/QVM10.1.1E5A.Malware.Gen

How to remove Win32/Injector.Autoit.DAA?

Win32/Injector.Autoit.DAA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment