Malware

Win32/Injector.Autoit.EYG removal tips

Malware Removal

The Win32/Injector.Autoit.EYG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.EYG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself

How to determine Win32/Injector.Autoit.EYG?


File Info:

crc32: 25BC1FC0
md5: 3969622477d3a8e666cde277769e8aa0
name: 3969622477D3A8E666CDE277769E8AA0.mlw
sha1: 837d8379a903dc6a91d9b99e5fff1e17d9ba1ff5
sha256: 92702ede9edc888bc897967388923c0ced4a6bbcaab287a11a858849a15e9420
sha512: 0e4ffcb110f12444a4d64223184a8c01a3fa7138ae6e1e052e98c12428c875cb6da565f85b786aece8e9acf40db13407c1014d9d3fa6bafc23f814df2f96a041
ssdeep: 49152:Zu0c++OCvkGs9FaVFBQ6I/PWAfAXZraU4Y:MB3vkJ9MbJej
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Win32/Injector.Autoit.EYG also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.AutoIt.4!e
Elasticmalicious (high confidence)
DrWebTrojan.Inject3.33479
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.32970723
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/AutoitU.ali2000008
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.477d3a
CyrenW32/AutoIt.NL.gen!Eldorado
SymantecPacked.Generic.548
ESET-NOD32a variant of Win32/Injector.Autoit.EYG
APEXMalicious
AvastAutoIt:Injector-JR [Trj]
KasperskyTrojan-Dropper.Win32.Agentoit.om
BitDefenderTrojan.GenericKD.32970723
NANO-AntivirusTrojan.Win32.Inject3.gvdtlf
MicroWorld-eScanTrojan.GenericKD.32970723
TencentWin32.Trojan-dropper.Agentoit.Lknx
Ad-AwareTrojan.GenericKD.32970723
SophosMal/Generic-R + Troj/Steal-DD
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.AutoIt.NEGASTEAL.SM.hp
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.3969622477d3a8e6
EmsisoftTrojan.GenericKD.32970723 (B)
AviraHEUR/AGEN.1100122
Antiy-AVLTrojan/Generic.ASCommon.1B8
MicrosoftTrojan:Win32/Occamy.C92
ArcabitTrojan.Generic.D1F717E3
GDataTrojan.GenericKD.32970723
AhnLab-V3Trojan/AU3.Wacatac.S1079
McAfeeArtemis!3969622477D3
MAXmalware (ai score=81)
VBA32Trojan.Wacatac
MalwarebytesTrojan.MalPack.AutoIt.Generic
PandaTrj/CI.A
TrendMicro-HouseCallTrojanSpy.AutoIt.NEGASTEAL.SM.hp
RisingTrojan.Obfus/Autoit!1.C045 (CLASSIC)
IkarusTrojan-Spy.Keylogger.AgentTesla
MaxSecureTrojan.Malware.74740588.susgen
FortinetAutoIt/Injector.ESJ!tr
AVGAutoIt:Injector-JR [Trj]
Paloaltogeneric.ml

How to remove Win32/Injector.Autoit.EYG?

Win32/Injector.Autoit.EYG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment