Malware

About “Win32/Injector.Autoit.EEN” infection

Malware Removal

The Win32/Injector.Autoit.EEN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.EEN virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to bypass application whitelisting by executing .NET utility in a suspended state, potentially for injection
  • CAPE detected the HawkEyev9 malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Win32/Injector.Autoit.EEN?


File Info:

name: 64B0C1B07CFA8BBBCB54.mlw
path: /opt/CAPEv2/storage/binaries/a850211dafa1401fad7430d25aa5b14ee9b6886b48524318a8a62e5f2b730848
crc32: 5CFA29F5
md5: 64b0c1b07cfa8bbbcb54f8f5e7552570
sha1: 4249cbcf052f267ce5a9603801b47742b7a85f52
sha256: a850211dafa1401fad7430d25aa5b14ee9b6886b48524318a8a62e5f2b730848
sha512: b6ff981a7cc207bc55836bd78aa9ed49e854554befe5bfc7f254ab0f212f312e179011a13e6505f593b4a33179859509cab694c5a46270bf65309e0b9f9ac05e
ssdeep: 24576:KAHnh+eWsN3skA4RV1Hom2KXMmHaQGxp3Wl06HDKW93kkOkA6P6R7oX+rXa5:dh+ZkldoPK8YaQGj3WlVj53ARxg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F75DF0273D1D036FFAAA2739B6AF24556BC79250133892F13981DB9BD701B1263E763
sha3_384: 843b4643c6f74cdea64dbdfa6733707b3bf2ec2dbaec2067ed5051013b06f0f6db0e7a5e8af627f48ab2abdc6676557c
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-08-05 07:57:31

Version Info:

FileDescription: control
OriginalFilename: mcbuilder
CompanyName: efsui
FileVersion: 36.360.392.491
LegalCopyright: AxInstSv
ProductName: choice
ProductVersion: 148.74.902.228
Translation: 0x0409 0x04b0

Win32/Injector.Autoit.EEN also known as:

BkavW32.AIDetect.malware2
LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.26208
MicroWorld-eScanGen:Trojan.Heur.AutoIT.16
FireEyeGeneric.mg.64b0c1b07cfa8bbb
CAT-QuickHealTrojan.AutoIt.Skeeyah.ZZ
McAfeeArtemis!64B0C1B07CFA
CylanceUnsafe
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojanPSW:Win32/CryptInject.8ab3f0a9
K7GWTrojan ( 700000111 )
Cybereasonmalicious.07cfa8
BitDefenderThetaAI:Packer.4619F3A015
CyrenW32/AutoIt.TB.gen!Eldorado
SymantecInfostealer
ESET-NOD32a variant of Win32/Injector.Autoit.EEN
TrendMicro-HouseCallBackdoor.AutoIt.BLADABINDI.SMA.hp
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Heye.ibx
BitDefenderGen:Trojan.Heur.AutoIT.16
NANO-AntivirusTrojan.Win32.Heye.fvcbfo
AvastWin32:Malware-gen
RisingTrojan.Injector/Autoit!1.BB82 (CLASSIC)
SophosMal/Generic-S + Mal/AuItInj-A
ComodoMalware@#3o39oya54pzrv
VIPRETrojan.Win32.Generic!BT
TrendMicroBackdoor.AutoIt.BLADABINDI.SMA.hp
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftGen:Trojan.Heur.AutoIT.16 (B)
AviraHEUR/AGEN.1245429
Antiy-AVLTrojan/Generic.ASCommon.16E
MicrosoftTrojan:Win32/CryptInject
ZoneAlarmTrojan-PSW.Win32.Heye.ibx
GDataGen:Trojan.Heur.AutoIT.16
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Autoinj03.Exp
ALYacGen:Trojan.Heur.AutoIT.16
VBA32Trojan.Autoit.Injcrypt
MalwarebytesTrojan.MalPack.AutoIt
APEXMalicious
TencentWin32.Trojan-qqpass.Qqrob.Wpjk
IkarusTrojan.Autoit
MaxSecureTrojan.Malware.74094671.susgen
FortinetAutoIt/Injector.EER!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.Autoit.EEN?

Win32/Injector.Autoit.EEN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment