Malware

Win32/Injector.Autoit.FBU removal instruction

Malware Removal

The Win32/Injector.Autoit.FBU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.FBU virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
BRHlEL.BRHlEL

How to determine Win32/Injector.Autoit.FBU?


File Info:

crc32: 7FB5F2BF
md5: 5c8f76ef10a7d2493dec6399c4225a73
name: upload_file
sha1: f40891e66c3b6a568a822a6a09868370ea80a3a1
sha256: 637d172395f876a73f77476c2ab1261e289b8f12395110627a7c93583b11c868
sha512: b244a4e76d4fa9b73008bac323443f0c26e9a6053550c0b7ae174b7434ae4a28f9d2982995ec999c91cfd3945f0a248ee4c95dfd21b20569a8b0bca361f31f0c
ssdeep: 24576:YQEhMzeNJBjAObi4M2rIDTU4fmj6J/d5JJXuE6YBp5:YQEhM8BfbiyrIDovj6llJXv6YB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Lorem Thousands Blind Long
InternalName: Lorem Thousands Blind Long
FileVersion: 53.81.94
CompanyName: Lorem Thousands Blind Long
LegalTrademarks: Lorem Thousands Blind Long
Comments: Lorem Thousands Blind Long
ProductName: Lorem Thousands Blind Long
ProductVersion: 53.81.94
FileDescription: Lorem Thousands Blind Long
OriginalFilename: Lorem Thousands Blind Long.exe
Translation: 0x0409 0x04b0

Win32/Injector.Autoit.FBU also known as:

MicroWorld-eScanTrojan.GenericKD.34265706
FireEyeGeneric.mg.5c8f76ef10a7d249
Qihoo-360Generic/Trojan.55f
McAfeeArtemis!5C8F76EF10A7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.BAT.Generic.4!c
K7AntiVirusTrojan ( 00562f171 )
BitDefenderTrojan.GenericKD.34265706
K7GWTrojan ( 00562f171 )
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.34265706
KasperskyHEUR:Trojan.BAT.Generic
AlibabaTrojan:Win32/Injector.dff6d7fc
ViRobotTrojan.Win32.Z.Autoit.1053104
Ad-AwareTrojan.GenericKD.34265706
EmsisoftTrojan.GenericKD.34265706 (B)
F-SecureTrojan.TR/AutoIt.pgzgo
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
WebrootW32.Trojan.Gen
AviraTR/AutoIt.pgzgo
MAXmalware (ai score=84)
ArcabitTrojan.Generic.D20ADA6A
ZoneAlarmHEUR:Trojan.BAT.Generic
MicrosoftTrojan:Win32/Casdet!rfn
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.34265706
MalwarebytesTrojan.Injector
ESET-NOD32Win32/Injector.Autoit.FBU
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Win32/Injector.Autoit.FBU?

Win32/Injector.Autoit.FBU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment