Malware

Should I remove “Win32/Injector.Autoit.DYR”?

Malware Removal

The Win32/Injector.Autoit.DYR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.DYR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Injector.Autoit.DYR?


File Info:

name: 07D6C51F58D36EF934D1.mlw
path: /opt/CAPEv2/storage/binaries/2e41dd9657d76d8944c2781575d2151b496248e175ff664c2f4c22d9f8855e88
crc32: 3CA17114
md5: 07d6c51f58d36ef934d17c4f6b8b25e6
sha1: 6cf088aee78a2deb0945f49529a276711b0dc966
sha256: 2e41dd9657d76d8944c2781575d2151b496248e175ff664c2f4c22d9f8855e88
sha512: fb6ef9cd87dbba0e0dd84129e1ee7e444a53a229e59bdf3a664a2e7dcd030b450f545f79b209e553186982379f936ab3ac3807b101e1c4bdfd67d638142e5045
ssdeep: 24576:XAHnh+eWsN3skA4RV1Hom2KXMmHaTS+Nrg5dbt5b:Kh+ZkldoPK8YaTlNUdb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA258C0273918036FFAF92735B65B20156BDA9291123C93F12B85DB9B9701F12E2D36F
sha3_384: cf64d37cb4f0b98f3ffda6e017acf28f3a0a6f121e28f2a97dfef44c7da233c2b39f8b7faa345b3d2f8fb09f1819ee3b
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-05-21 16:21:46

Version Info:

FileDescription: UserAccountControlSettings
OriginalFilename: acledit
CompanyName: CloudExperienceHostBroker
FileVersion: 204.924.610.214
LegalCopyright: WallpaperHost
ProductName: AppVScripting
ProductVersion: 171.617.816.278
Translation: 0x0409 0x04b0

Win32/Injector.Autoit.DYR also known as:

BkavW32.AIDetectMalware
LionicTrojan.Script.Generic.4!c
MicroWorld-eScanGen:Trojan.Heur.AutoIT.16
FireEyeGeneric.mg.07d6c51f58d36ef9
ALYacGen:Trojan.Heur.AutoIT.16
MalwarebytesGeneric.Trojan.Injector.DDS
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/AutoitCrypt.180
K7GWTrojan ( 700000111 )
Cybereasonmalicious.f58d36
CyrenW32/AutoIt.JL.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.Autoit.DYR
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Remcos-6986981-0
KasperskyHEUR:Trojan.Script.Generic
BitDefenderGen:Trojan.Heur.AutoIT.16
NANO-AntivirusTrojan.Win32.AutoIt.gqejjn
AvastAutoIt:Injector-JF [Trj]
TencentWin32.Trojan.Generic.Vwhl
SophosMal/AuItInj-A
F-SecureHeuristic.HEUR/AGEN.1321294
DrWebTrojan.AutoIt.452
VIPREGen:Trojan.Heur.AutoIT.16
TrendMicroBackdoor.AutoIt.BLADABINDI.SMA.hp
McAfee-GW-EditionBehavesLike.Win32.Injector.dh
EmsisoftGen:Trojan.Heur.AutoIT.16 (B)
IkarusTrojan.Autoit
GDataGen:Trojan.Heur.AutoIT.16
GoogleDetected
AviraHEUR/AGEN.1321294
Antiy-AVLGrayWare/Autoit.ShellCode.a
ArcabitTrojan.Heur.AutoIT.16
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/AutoInj.Exp
Acronissuspicious
McAfeeArtemis!07D6C51F58D3
MAXmalware (ai score=86)
VBA32Trojan-Downloader.Autoit.gen
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBackdoor.AutoIt.BLADABINDI.SMA.hp
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
FortinetAutoIt/Injector.EAH!tr
BitDefenderThetaAI:Packer.0E292DA617
AVGAutoIt:Injector-JF [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.Autoit.DYR?

Win32/Injector.Autoit.DYR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment