Malware

Win32/Injector.Autoit.FCH removal instruction

Malware Removal

The Win32/Injector.Autoit.FCH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.Autoit.FCH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
nass1144.ddns.net

How to determine Win32/Injector.Autoit.FCH?


File Info:

crc32: 1802ADA3
md5: cd92c9455df907fdde0abda2e2d66c20
name: new.exe
sha1: 5de23d32a4bd8cbda049ebb0c3b2405a805e75c5
sha256: 70e2269739698e20a20e46fb7aec538c9788dd1f1bd9e586c47dc336a537682d
sha512: a084af9e8685f1cf9d55c5f28ece219bbaca4e7f66ce444f77b092fe8c8ebcf53abf5ce316240535208ca2fb3fbd6f2578149aa248df65c3c1774c0ed2b5d17b
ssdeep: 24576:fu6J33O0c+JY5UZ+XC0kGso6FaLqwFxPBRLnia+8ZsZybE7uYr9knyKU0ntk3yW:pu0c++OCvkGs9FaWwxK8GywaM9kyKUY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Win32/Injector.Autoit.FCH also known as:

MicroWorld-eScanTrojan.GenericKD.42605746
FireEyeGeneric.mg.cd92c9455df907fd
McAfeeArtemis!CD92C9455DF9
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42605746
K7GWRiskware ( 0040eff71 )
F-ProtW32/AutoIt.NS.gen!Eldorado
SymantecPacked.Generic.548
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.42605746
KasperskyHEUR:Trojan.Script.Generic
AlibabaTrojan:Win32/AutoitU.ali2000008
AegisLabTrojan.Script.Generic.4!c
RisingTrojan.Obfus/Autoit!1.C045 (CLASSIC)
Ad-AwareTrojan.GenericKD.42605746
EmsisoftTrojan.Autoit (A)
F-SecureTrojan.TR/AD.BDSNanoCoreClient.vdzau
DrWebTrojan.KillProc2.8861
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Autoit
CyrenW32/AutoIt.NS.gen!Eldorado
MaxSecureTrojan.Malware.300983.susgen
AviraTR/AD.BDSNanoCoreClient.vdzau
MAXmalware (ai score=81)
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D28A1CB2
ZoneAlarmHEUR:Trojan.Script.Generic
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Trojan/AU3.Wacatac.S1079
ALYacBackdoor.RAT.MSIL.NanoCore
MalwarebytesTrojan.MalPack.AutoIt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.FCH
TencentWin32.Trojan.Agent.Auto
FortinetAutoIt/Injector.FCH!tr
AVGScript:SNH-gen [Trj]
AvastScript:SNH-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Generic/Trojan.Script.ed4

How to remove Win32/Injector.Autoit.FCH?

Win32/Injector.Autoit.FCH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment