Malware

What is “Win32/Injector.Autoit.DUS”?

Malware Removal

The Win32/Injector.Autoit.DUS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.DUS virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Injector.Autoit.DUS?


File Info:

name: 58EC18F9EC9482477105.mlw
path: /opt/CAPEv2/storage/binaries/d89059ff960f80ab792e67500895878bc08c615c07e0e4c90490570c875f4f69
crc32: A2EF0035
md5: 58ec18f9ec94824771053fc9fac98523
sha1: 61c132e07b89a00468046d782c06cefdae4f594a
sha256: d89059ff960f80ab792e67500895878bc08c615c07e0e4c90490570c875f4f69
sha512: 9fc06a3b45ebefedcee58320e2b394285b94b2ab4617d0b6a50f80044f381f58109142a9e7b44dc532e9db6d5f037bebc037edbeeb71664c406e5910c70013a4
ssdeep: 24576:BAHnh+eWsN3skA4RV1Hom2KXMmHaispbkS5XGp0l5:Yh+ZkldoPK8YaiF0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B65C042A3E5C0F2FE5666B39F25B6825B7C69314533402E23992D6DBD720B2423DB73
sha3_384: 98d6b25ac5b5d5241e6daea891e0764731ce7cebf3110b8bd2cff27c8950f4733bcece3323efd6d2dca55c9c3bdc5226
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-03-17 21:39:16

Version Info:

Translation: 0x0809 0x04b0

Win32/Injector.Autoit.DUS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Script.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.31805597
SkyhighBehavesLike.Win32.TrojanAitInject.th
McAfeeArtemis!58EC18F9EC94
MalwarebytesGeneric.Malware/Suspicious
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 0054a1041 )
AlibabaTrojan:Win32/AutInject.6fec65fe
K7GWTrojan ( 0054a1041 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D1E5509D
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.Autoit.DUS
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.Script.Obit.gen
BitDefenderTrojan.GenericKD.31805597
NANO-AntivirusTrojan.Win32.AutoIt.foeole
AvastAutoIt:Injector-JF [Trj]
TencentScript.Trojan.Obit.Yimw
EmsisoftTrojan.GenericKD.31805597 (B)
F-SecureHeuristic.HEUR/AGEN.1319331
DrWebTrojan.AutoIt.346
VIPRETrojan.GenericKD.31805597
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
FireEyeGeneric.mg.58ec18f9ec948247
SophosMal/AuItInj-A
SentinelOneStatic AI – Malicious PE
VaristW32/AutoIt.RE.gen!Eldorado
AviraHEUR/AGEN.1319331
MAXmalware (ai score=88)
Antiy-AVLGrayWare/Autoit.ShellCode.a
Kingsoftmalware.kb.a.1000
XcitiumMalware@#1pz6f39b8696y
MicrosoftVirTool:Win32/AutInject.CZ!bit
ZoneAlarmTrojan.Script.Obit.gen
GDataTrojan.GenericKD.31805597
GoogleDetected
AhnLab-V3Win-Trojan/AutoInj.Exp
BitDefenderThetaAI:Packer.E2F7478417
ALYacTrojan.GenericKD.31805597
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
RisingTrojan.Injector/Autoit!1.BBE6 (CLASSIC)
IkarusTrojan.Autoit
MaxSecureTrojan.Malware.74719580.susgen
FortinetAutoIt/Injector.DUY!tr
AVGAutoIt:Injector-JF [Trj]
Cybereasonmalicious.07b89a
DeepInstinctMALICIOUS

How to remove Win32/Injector.Autoit.DUS?

Win32/Injector.Autoit.DUS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment