Malware

Win32/Injector.Autoit.DZK (file analysis)

Malware Removal

The Win32/Injector.Autoit.DZK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.DZK virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the Remcos malware family
  • Creates a copy of itself
  • Creates known Remcos mutexes
  • Creates known Remcos registry keys
  • Anomalous binary characteristics

How to determine Win32/Injector.Autoit.DZK?


File Info:

name: 99EA0501FD50A3A27A20.mlw
path: /opt/CAPEv2/storage/binaries/142f9b0942702963f327c5f7ab4f4a21c7886c1d0d59c28b47c224bfff52fa2b
crc32: 65050F57
md5: 99ea0501fd50a3a27a201ff2be794df8
sha1: dd7f53946174cf3299d2a160e2c54d2298bea6c0
sha256: 142f9b0942702963f327c5f7ab4f4a21c7886c1d0d59c28b47c224bfff52fa2b
sha512: a84799b1fbc187a71db2c0059230ff92fe86e496f04c870c38ee3f64b167f5200323e0ef6ef47c1b0004a2a2e5657d1d77b4df7442204da8902f6b0cdb378d14
ssdeep: 24576:QAHnh+eWsN3skA4RV1Hom2KXFmIalKCc9GS5E:Hh+ZkldoPK1XalKCc9nE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC259C0273D1C036FFABA2739B6AF24156BD79354123852F13981DB9BD701B2263E663
sha3_384: 7bce44fb6b92bfcc50ab857d3d240df2486a813959c93721f7069e5e7d29c3ac3ec710afe9b1fd1be7222c4b21690df2
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-05-30 10:20:13

Version Info:

Translation: 0x0809 0x04b0

Win32/Injector.Autoit.DZK also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.32026646
FireEyeGeneric.mg.99ea0501fd50a3a2
CAT-QuickHealTrojan.AutoIt.AitInject.ZZ
McAfeeTrojan-AitInject.aq
CylanceUnsafe
K7AntiVirusTrojan ( 0054f1021 )
K7GWTrojan ( 0054f1021 )
Cybereasonmalicious.1fd50a
BitDefenderThetaAI:Packer.9A3D7CD617
CyrenW32/AutoIt.QF.gen!Eldorado
SymantecPacked.Generic.548
ESET-NOD32a variant of Win32/Injector.Autoit.DZK
ClamAVWin.Malware.Remcos-6985942-1
KasperskyTrojan-Downloader.Win32.AutoIt.aop
BitDefenderTrojan.GenericKD.32026646
NANO-AntivirusTrojan.Script.Downloader.iuwddd
AvastAutoIt:Injector-JF [Trj]
TencentMalware.Win32.Gencirc.10b4d525
Ad-AwareTrojan.GenericKD.32026646
SophosML/PE-A + Troj/AutoIt-CMZ
DrWebTrojan.Packed2.41759
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftTrojan.GenericKD.32026646 (B)
APEXMalicious
GDataTrojan.GenericKD.32026646
eGambitUnsafe.AI_Score_95%
AviraTR/AD.Remcos.vsbwu
Antiy-AVLTrojan/Generic.ASCommon.151
ArcabitTrojan.Generic.D1E8B016
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/AutoInj.Exp
VBA32Backdoor.Remcos
ALYacTrojan.GenericKD.32026646
MalwarebytesTrojan.MalPack.Generic
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
IkarusTrojan.Autoit
MaxSecureWin.MxResIcn.Heur.Gen
FortinetAutoIt/Injector.DZH!tr
AVGAutoIt:Injector-JF [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Win32/Injector.Autoit.DZK?

Win32/Injector.Autoit.DZK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment