Malware

Win32/Injector.Autoit.EDD removal tips

Malware Removal

The Win32/Injector.Autoit.EDD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.EDD virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to bypass application whitelisting by executing .NET utility in a suspended state, potentially for injection
  • Anomalous binary characteristics

How to determine Win32/Injector.Autoit.EDD?


File Info:

name: 159F5406657B686BC049.mlw
path: /opt/CAPEv2/storage/binaries/768a16c73efb3fac7f07d86715a2c71f4b4f1e071d90f7d698dae805ed96a42b
crc32: A994ADBD
md5: 159f5406657b686bc04949702d2fc692
sha1: 070e21c32e68c0477cbbcdabdf505a741fa093da
sha256: 768a16c73efb3fac7f07d86715a2c71f4b4f1e071d90f7d698dae805ed96a42b
sha512: 70d282a4cdcd8dda6fe3b66c7f2deb4767e6a30b4b517c16db37a0910eead99bb86f878e928079cb1074ec8dcbea1d86bdd72a14485d7965b3f1c87ca28d12eb
ssdeep: 24576:tAHnh+eWsN3skA4RV1Hom2KXSmdaERgO1IVH0ccf5qX19CikJMG2YYCprlRv5:Mh+ZkldoPKi2aET1Crcivnkb5lP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD65DF0273D2C036FFAB92739B6AF64156BC79254123852F13982DB9BC701B2267D763
sha3_384: 65a9350389bc3bfd8366dc3212181335fc8d402c1ee7b1dbc876adba439d168b1aa4aefaf0c7d588f9010e45487b8b60
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-07-04 19:41:02

Version Info:

FileDescription: setspn
OriginalFilename: cttune
CompanyName: Windows.WARP.JITService
FileVersion: 494.468.404.487
LegalCopyright: ntoskrnl
ProductName: sc
ProductVersion: 871.464.953.772
Translation: 0x0409 0x04b0

Win32/Injector.Autoit.EDD also known as:

LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.AutoIT.16
CAT-QuickHealTrojan.GenericSM.S6640062
McAfeeArtemis!159F5406657B
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/AutoitCrypt.180
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/AutoIt.QF.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.Autoit.EDD
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Androm.sttv
BitDefenderGen:Trojan.Heur.AutoIT.16
NANO-AntivirusTrojan.Win32.Androm.fthwpf
AvastAutoIt:Injector-JM [Trj]
TencentWin32.Trojan.Autoit.Auto
Ad-AwareGen:Trojan.Heur.AutoIT.16
EmsisoftGen:Trojan.Heur.AutoIT.16 (B)
ComodoMalware@#3qw3gsho4exsz
DrWebTrojan.AutoIt.457
VIPRETrojan.Win32.Generic!BT
TrendMicroBackdoor.AutoIt.BLADABINDI.SMA.hp
SophosMal/Generic-S + Mal/AuItInj-A
AviraHEUR/AGEN.1207793
ArcabitTrojan.Heur.AutoIT.16
MicrosoftVirTool:Win32/AutInject.DE!bit
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Autoinj03.Exp
ALYacGen:Trojan.Heur.AutoIT.16
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallBackdoor.AutoIt.BLADABINDI.SMA.hp
RisingTrojan.Obfus/Autoit!1.C075 (CLASSIC)
IkarusVirus.Win32.AutInject
eGambitUnsafe.AI_Score_98%
FortinetAutoIt/Injector.DZY!tr
AVGAutoIt:Injector-JM [Trj]
PandaTrj/Genetic.gen

How to remove Win32/Injector.Autoit.EDD?

Win32/Injector.Autoit.EDD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment