Trojan

About “Trojan.Win32.Pincav.yl” infection

Malware Removal

The Trojan.Win32.Pincav.yl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Pincav.yl virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Operates on local firewall’s policies and settings
  • Deletes executed files from disk
  • Attempts to disable Windows Auto Updates
  • Attempts to modify or disable Security Center warnings
  • Modifies Image File Execution Options, indicative of process injection or persistence
  • Anomalous binary characteristics

How to determine Trojan.Win32.Pincav.yl?


File Info:

name: 870DB438342C2D112EB1.mlw
path: /opt/CAPEv2/storage/binaries/4ff3877a40a0d43cd1c046c5ddabea82b1ef8c6d5cd3cee7c0eceb1f0f0ce6ca
crc32: EEDFE44E
md5: 870db438342c2d112eb1fa531ea51949
sha1: 51c3941536afa6410906a7f9df23584c958102d2
sha256: 4ff3877a40a0d43cd1c046c5ddabea82b1ef8c6d5cd3cee7c0eceb1f0f0ce6ca
sha512: 4299d748ad5bc2a4ca8f43ea1924062f5f093ca50f00b0d4b974886c21dd7f3ceea38ee7f81fad10ed8bd81277d48b4440f580b84ce50aa4bb8336e52bccfe16
ssdeep: 1536:1YF8NLCofRLCg/pdsHT+obdo8Cgzvl4ooofgke253r:uF+LCofRLCgxSzXo8CgpIo53r
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106635D732D017EDAEA2D563732FB71A515A198E3E8BE454EFF061CAA015127B138B307
sha3_384: 2c8e73e34741ec33c4583cb573a24593228febaae404b9b83c8c3018bed7d7dd08983b830703569b183376db3c68e1ed
ep_bytes: 5557565381ecc8090000c78424bc0000
timestamp: 2008-08-04 21:06:40

Version Info:

0: [No Data]

Trojan.Win32.Pincav.yl also known as:

BkavW32.AIDetectMalware
DrWebTrojan.DownLoad.24167
MicroWorld-eScanGen:Trojan.Heur.eiZ@HDhoAsp
FireEyeGeneric.mg.870db438342c2d11
SkyhighBehavesLike.Win32.Downloader.lh
McAfeeGenericRXAA-AA!870DB438342C
Cylanceunsafe
ZillyaDownloader.Agent.Win32.329213
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Heur.ED2AFF
BitDefenderThetaAI:Packer.C9D8CB431B
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.NIV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Hdhoasp-10019465-0
KasperskyTrojan.Win32.Pincav.yl
BitDefenderGen:Trojan.Heur.eiZ@HDhoAsp
NANO-AntivirusTrojan.Win32.DownLoad.cwygmt
AvastWin32:DropperX-gen [Drp]
TencentMalware.Win32.Gencirc.10b53801
SophosMal/Behav-009
F-SecureTrojan.TR/Downloader.Gen
VIPREGen:Trojan.Heur.eiZ@HDhoAsp
EmsisoftGen:Trojan.Heur.eiZ@HDhoAsp (B)
IkarusTrojan-Downloader.Win32.Agent
JiangminTrojan/Pincav.ejs
VaristW32/Dropper.6!Generic
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Win32.Pincav
Kingsoftmalware.kb.a.997
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ZoneAlarmTrojan.Win32.Pincav.yl
GDataGen:Trojan.Heur.eiZ@HDhoAsp
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R347076
VBA32BScope.TrojanDownloader.Agent
ALYacGen:Trojan.Heur.eiZ@HDhoAsp
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.XOR.Generic
PandaGeneric Suspicious
RisingTrojan.Occamy!8.F1CD (TFE:2:kcrHBZS9J4H)
YandexTrojan.GenAsa!qABkOaw0YR8
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.NIV!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.536afa
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Pincav.yl?

Trojan.Win32.Pincav.yl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment