Malware

About “Win32/Injector.Autoit.EYO” infection

Malware Removal

The Win32/Injector.Autoit.EYO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.EYO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Injector.Autoit.EYO?


File Info:

crc32: 81CBC837
md5: d38edf19034056e4f8ff61c60d46b0f5
name: 3b.exe
sha1: c0ec1b68c88a3d72c882462c886bdc6b2ccbac66
sha256: e24f1fca26cac9b90668dda1c610a454816c0b8837e89a720969bc0646031248
sha512: 7282faa81c6b44528fe500c1d7d186a4744ee900eba0923f7d1e6c27d9429d1825beb4d45ea92569c074a6a2223be976ff41bb7dfd9b940c9c7c0cd3f2121a95
ssdeep: 24576:9u6J33O0c+JY5UZ+XC0kGso6FaFVSHLV15O7MAQ79WY:Pu0c++OCvkGs9FaFVSHvwAOY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Win32/Injector.Autoit.EYO also known as:

MicroWorld-eScanTrojan.GenericKD.42278966
CAT-QuickHealTrojan.Multi
McAfeeArtemis!D38EDF190340
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKD.42278966
K7GWTrojan ( 0055f43d1 )
K7AntiVirusTrojan ( 0055f43d1 )
ArcabitTrojan.Generic.D2852036
CyrenW32/Trojan.OGCN-1765
SymantecPacked.Generic.548
ESET-NOD32a variant of Win32/Injector.Autoit.EYO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Azorult.ajwg
AlibabaTrojanPSW:Win32/Azorult.271e2fee
RisingTrojan.Obfus/Autoit!1.C075 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42278966 (B)
F-SecureTrojan.TR/AD.MoksSteal.evpx
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
FortinetAutoIt/Injector.ESJ!tr
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.d38edf19034056e4
SophosMal/Generic-S
AviraTR/AD.MoksSteal.evpx
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Predator.BC!MTB
ZoneAlarmTrojan-PSW.Win32.Azorult.ajwg
ALYacTrojan.GenericKD.42278966
Ad-AwareTrojan.GenericKD.42278966
TrendMicro-HouseCallTROJ_GEN.R020H01AM20
TencentWin32.Trojan-qqpass.Qqrob.Wqmw
IkarusTrojan-Spy.Keylogger.AgentTesla
eGambitUnsafe.AI_Score_69%
GDataTrojan.GenericKD.42278966
AVGFileRepMalware
Cybereasonmalicious.8c88a3
AvastFileRepMalware
Qihoo-360Win32/Trojan.PSW.31f

How to remove Win32/Injector.Autoit.EYO?

Win32/Injector.Autoit.EYO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment