Malware

What is “Win32/Injector.Autoit.DYL”?

Malware Removal

The Win32/Injector.Autoit.DYL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.DYL virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Anomalous binary characteristics

Related domains:

ucpoinsr.myjino.ru

How to determine Win32/Injector.Autoit.DYL?


File Info:

crc32: B1C4949E
md5: 0a3ca5826339e78398a2207b26e1c07b
name: sniper.exe
sha1: 682cfc1a580d06b08c2a6949a384fc0d456a7aa0
sha256: 848a51a7f9d0e2d534353e876919c28202ff2f64a8b8b9df5d4900013819838c
sha512: e0259331389960d9f027499cb2d495dfb337e55a4604dca7add2574249ba7fcd3871bf4fe8873efc2efcf9980070b83673fa4fc7f67a212f67f75b80f9a6011c
ssdeep: 24576:WAHnh+eWsN3skA4RV1Hom2KXSmdagdbFP/8VrJ2LicUE0BTE5:xh+ZkldoPKi2agd5/qF2LiNZG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: authz
FileVersion: 82.257.804.258
CompanyName: EASPolicyManagerBrokerHost
ProductName: odbcconf
ProductVersion: 318.157.41.521
FileDescription: mobsync
OriginalFilename: MaxxAudioMeters64
Translation: 0x0409 0x04b0

Win32/Injector.Autoit.DYL also known as:

MicroWorld-eScanTrojan.GenericKD.31987683
FireEyeGeneric.mg.0a3ca5826339e783
Qihoo-360HEUR/QVM10.2.44BF.Malware.Gen
McAfeeArtemis!0A3CA5826339
MalwarebytesTrojan.MalPack.Generic
AegisLabTrojan.Win32.Generic.4!c
BitDefenderTrojan.GenericKD.31987683
K7GWTrojan ( 0054e5d81 )
K7AntiVirusTrojan ( 0054e5d81 )
Invinceaheuristic
NANO-AntivirusTrojan.Win32.Predator.fqkspy
CyrenW32/Trojan.MNYK-0964
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.31987683
KasperskyTrojan-PSW.Win32.Predator.agz
AlibabaTrojanPSW:Win32/Predator.db0cba28
ViRobotTrojan.Win32.Z.Sonbokli.1316869
TencentWin32.Trojan.Autoit.Auto
Ad-AwareTrojan.GenericKD.31987683
SophosMal/Generic-S
DrWebTrojan.PWS.Siggen2.15009
TrendMicroTROJ_GEN.R002C0WEJ19
McAfee-GW-EditionBehavesLike.Win32.Downloader.th
EmsisoftTrojan.GenericKD.31987683 (B)
SentinelOneDFI – Malicious PE
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1E817E3
ZoneAlarmTrojan-PSW.Win32.Predator.agz
MicrosoftTrojan:Win32/Tiggre!plock
AhnLab-V3Malware/Win32.Generic.C3253020
Acronissuspicious
ALYacTrojan.GenericKD.31987683
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.Autoit.DYL
TrendMicro-HouseCallTROJ_GEN.R002C0WEJ19
RisingTrojan.Win32.Agent_.rm (CLASSIC)
IkarusTrojan.Win32.Injector
FortinetW32/Autoit.DYL!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.74324987.susgen

How to remove Win32/Injector.Autoit.DYL?

Win32/Injector.Autoit.DYL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment