Malware

Win32/Injector.Autoit.FAD removal

Malware Removal

The Win32/Injector.Autoit.FAD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.FAD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Harvests information related to installed mail clients

How to determine Win32/Injector.Autoit.FAD?


File Info:

crc32: E3FFD397
md5: 1c68f25d1ac2a08a8cf2c7e9f6ce5193
name: homel.exe
sha1: 91cda304a76e8bb42eed1f0b4c50923416659d86
sha256: 3a1f0c5f5f7c079a499839f718e86f50cde7c6668d9c9471d65ad87eb2b3361c
sha512: 209acbf474e042444391987b8fa7e1ee64645cbf57197a8adf3c80ede7ab1991230bd1465c3420e9d62f6e6bd38b9ff0c8ca0b473c937366f2a9fcfbabd0874f
ssdeep: 49152:Gu0c++OCvkGs9Fas0BsZ66HJCVJ0TWSqWY:JB3vkJ9s6HJCVJ0CSqW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: igfxHK
CompanyName: dpapimig
ProductName: ssh-agent
ProductVersion: 74, 48, 453, 339
FileDescription: taskhostw
OriginalFilename: printfilterpipelinesvc.exe
Translation: 0x0000 0x04b0

Win32/Injector.Autoit.FAD also known as:

DrWebTrojan.PWS.Siggen2.42726
MicroWorld-eScanTrojan.GenericKD.42331442
FireEyeTrojan.GenericKD.42331442
Qihoo-360Win32/Trojan.Dropper.20c
ALYacTrojan.GenericKD.42331442
MalwarebytesTrojan.MalPack.AutoIt
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderTrojan.GenericKD.42331442
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTrojan.Win32.WACATAC.THBOCBO
F-ProtW32/AutoIt.NS.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.42331442
KasperskyTrojan-Dropper.Win32.Autit.njc
AlibabaTrojanDropper:Win32/Autit.5f0fc9fd
AvastWin32:Malware-gen
RisingTrojan.Obfus/Autoit!1.C045 (CLASSIC)
Ad-AwareTrojan.GenericKD.42331442
EmsisoftTrojan.GenericKD.42331442 (B)
F-SecureTrojan.TR/Autoit.pmxkg
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.HawkEye
CyrenW32/Trojan.MHKU-7892
AviraTR/Autoit.pmxkg
MAXmalware (ai score=87)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D285ED32
ZoneAlarmTrojan-Dropper.Win32.Autit.njc
MicrosoftTrojan:Win32/Predator.BC!MTB
AhnLab-V3Trojan/Win32.AutoInj.R279467
McAfeeArtemis!1C68F25D1AC2
CylanceUnsafe
ESET-NOD32a variant of Win32/Injector.Autoit.FAD
TrendMicro-HouseCallTrojan.Win32.WACATAC.THBOCBO
TencentWin32.Trojan-dropper.Autit.Dzue
FortinetAutoIt/Injector.EZY!tr
AVGWin32:Malware-gen
Cybereasonmalicious.4a76e8
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Injector.Autoit.FAD?

Win32/Injector.Autoit.FAD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment