Malware

About “Win32/Injector.Autoit.ETZ” infection

Malware Removal

The Win32/Injector.Autoit.ETZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.ETZ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (254 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.Autoit.ETZ?


File Info:

crc32: 12FCFF5E
md5: d79cb1a0ba156cf97cc8c67b76e269f9
name: rvcccvcghfvc.exe
sha1: 659a57580ea7c9800e7226715cfcfc300a464a33
sha256: 0810f1e1b014228476c9a7f91d4202686d7509234ffa18cd43bf000336825eb3
sha512: e715f1a32d2ddc550cee84cd6a8d60addd4a63abba47c5ead1a39a9ef81f012b73864acfa859383b2bb9a167651ced295f8c2671378b088c0fcc77b0f71cdaaa
ssdeep: 24576:Au6J33O0c+JY5UZ+XC0kGso6FasvPQdIIRWY:qu0c++OCvkGs9FaQPwcY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Win32/Injector.Autoit.ETZ also known as:

MicroWorld-eScanTrojan.GenericKD.32868527
FireEyeTrojan.GenericKD.32868527
McAfeeArtemis!D79CB1A0BA15
ALYacTrojan.Ransom.Crysis
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
BitDefenderTrojan.GenericKD.32868527
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.80ea7c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.Autoit.ETZ
GDataTrojan.GenericKD.32868527
KasperskyTrojan.Win32.Swisyn.ftzp
ViRobotTrojan.Win32.Z.Highconfidence.1093632
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.32868527 (B)
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
Trapminemalicious.high.ml.score
APEXMalicious
CyrenW32/Trojan.HMGX-0976
MaxSecureTrojan.Malware.300983.susgen
ArcabitTrojan.Generic.D1F588AF
AhnLab-V3Win-Trojan/Autoinj05.Exp
ZoneAlarmTrojan.Win32.Swisyn.ftzp
MicrosoftTrojan:Win32/Wacatac.B!ml
MAXmalware (ai score=81)
Ad-AwareTrojan.GenericKD.32868527
MalwarebytesRansom.Phobos
YandexTrojan.AvsArher.bSQb5x
IkarusWin32.Outbreak
FortinetAutoIt/Injector.ETT!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Trojan.f30

How to remove Win32/Injector.Autoit.ETZ?

Win32/Injector.Autoit.ETZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment