Malware

Win32/Injector.Autoit.DR removal tips

Malware Removal

The Win32/Injector.Autoit.DR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.DR virus can do?

  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

www.bing.com
adf.ly
regecish.net
cdn.adf.ly

How to determine Win32/Injector.Autoit.DR?


File Info:

crc32: 07324352
md5: 4f51914e8c2ab1c82b554249c1d1a1c7
name: 4F51914E8C2AB1C82B554249C1D1A1C7.mlw
sha1: 0c68dd58ab1acc121f1c1bf79db688d2abadd767
sha256: b07f47b92cb40be1b758117f369a197880f7de796321ca6aca659f08836690fe
sha512: 2e7fa0fdbf600d00e284ea67e04e6b81c24a44e39165eb669d7c9541bdbfbc54a06d541995c4098c2d1c3c08c7136741601074b4b98fb4696dcb22f5c8d9214f
ssdeep: 12288:laWzgMg7v3qnCiMErQohh0F4CCJ8lny/QYIFB:UaHMv6Corjqny/QYIL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 6, 1
FileVersion: 3, 3, 6, 1
FileDescription:
Translation: 0x0809 0x04b0

Win32/Injector.Autoit.DR also known as:

K7AntiVirusTrojan ( 700000111 )
DrWebTrojan.Siggen7.59513
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.45923067
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.4660
K7GWTrojan ( 700000111 )
Cybereasonmalicious.e8c2ab
SymantecW32.IRCBot.NG
ESET-NOD32a variant of Win32/Injector.Autoit.DR
APEXMalicious
AvastAutoIt:MalOb-A [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.zzy
BitDefenderTrojan.GenericKD.45923067
NANO-AntivirusTrojan.Win32.Blocker.belylc
MicroWorld-eScanTrojan.GenericKD.45923067
TencentWin32.Trojan.Blocker.Pfjl
Ad-AwareTrojan.GenericKD.45923067
SophosMal/Generic-S
ComodoMalware@#2rvvqdnhthi19
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.11D213
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
FireEyeTrojan.GenericKD.45923067
EmsisoftTrojan.GenericKD.45923067 (B)
JiangminTrojan.Script.akxp
AviraTR/Rogue.8704813
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
AegisLabTrojan.Multi.Generic.4!c
GDataTrojan.GenericKD.45923067
McAfeeArtemis!4F51914E8C2A
MAXmalware (ai score=99)
VBA32Trojan.Autoit.Wirus
PandaTrj/Agent.MIZ
TrendMicro-HouseCallTROJ_SPNR.11D213
IkarusTrojan-Ransom.Blocker
FortinetAutoIt/Injector.DR!tr
AVGAutoIt:MalOb-A [Trj]
Paloaltogeneric.ml

How to remove Win32/Injector.Autoit.DR?

Win32/Injector.Autoit.DR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment