Malware

Win32/Injector.Autoit.ECD removal

Malware Removal

The Win32/Injector.Autoit.ECD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.ECD virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates known CypherIT/Frenchy Shellcode mutexes
  • Attempts to access Bitcoin/ALTCoin wallets
  • Touches a file containing cookies, possibly for information gathering
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Injector.Autoit.ECD?


File Info:

name: ECF252CF7D3106989D9E.mlw
path: /opt/CAPEv2/storage/binaries/88b41c298e84437f801fb7381b5936705eb4525c0e4fdc80c3c3e6dac74e4d5b
crc32: 23A24D25
md5: ecf252cf7d3106989d9e80c0a71d0de6
sha1: 2a02611500e6fad2396b9389a237f6b5a0591499
sha256: 88b41c298e84437f801fb7381b5936705eb4525c0e4fdc80c3c3e6dac74e4d5b
sha512: 51c577a382b1dd710242f9f100718a50b98c5ad0106a033c781ac5a3245415c6961e4915f3f44ffdd8e0f83b9edfa7e675f272b6147723527bfc4b853148ba66
ssdeep: 49152:oh+ZkldoPKi2a8bgyDQpEIzI6KtUCc/Ti473:J2cPKiMbv0mIcDwWe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10095E11277D5C032FFAB92739B66F24597BC6D214233C52F62983C79AE705B1262D223
sha3_384: 815b3b49e7e44ff7380377485cc7fd22b0fd13cc34c3231e76412bcfa3aa1eb4e35c1732de42da7467e671409477e014
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-06-30 11:59:06

Version Info:

Translation: 0x0809 0x04b0

Win32/Injector.Autoit.ECD also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.32103380
ClamAVWin.Malware.Autoit-7006706-0
FireEyeGeneric.mg.ecf252cf7d310698
ALYacTrojan.GenericKD.32103380
Cylanceunsafe
SangforTrojan.Win32.Autoit.ubzlp
K7AntiVirusTrojan ( 005513561 )
AlibabaTrojan:Win32/AutoitInject.f41dcbf9
K7GWTrojan ( 005513561 )
Cybereasonmalicious.f7d310
BitDefenderThetaAI:Packer.7AAAC95E17
SymantecPacked.Generic.458
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.Autoit.ECD
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Inject.aluhm
BitDefenderTrojan.GenericKD.32103380
AvastFileRepMalware [Trj]
TencentWin32.Trojan.FalseSign.Majl
EmsisoftTrojan.GenericKD.32103380 (B)
F-SecureHeuristic.HEUR/AGEN.1305069
DrWebTrojan.AutoIt.483
VIPRETrojan.GenericKD.32103380
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
McAfee-GW-EditionAUTOIT/Injector.al
SophosMal/AuItInj-A
GDataTrojan.GenericKD.32103380
JiangminTrojanDownloader.AutoIt.bbl
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1305069
Antiy-AVLGrayWare/Autoit.BinToStr.a
ArcabitTrojan.Generic.D1E9DBD4
ZoneAlarmTrojan.Win32.Inject.aluhm
MicrosoftTrojan:Win32/AutoitInject.BH!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Autoinj03.Exp
McAfeeArtemis!ECF252CF7D31
MAXmalware (ai score=100)
VBA32Trojan.Autoit.F
MalwarebytesTrojan.Injector.AutoIt
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
RisingTrojan.Obfus/Autoit!1.C608 (CLASSIC)
IkarusTrojan.Autoit
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Injector.Autoit.ECD?

Win32/Injector.Autoit.ECD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment