Malware

Win32/Injector.ANZV (file analysis)

Malware Removal

The Win32/Injector.ANZV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.ANZV virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Win32/Injector.ANZV?


File Info:

name: A79B3EF42649BC268549.mlw
path: /opt/CAPEv2/storage/binaries/c0cf648cfa8bacb42ffafa51a85a886486ee832935afc2fa5da212dfef9f5720
crc32: A722406F
md5: a79b3ef42649bc268549c74e1ac5ac86
sha1: 1408783e5f40db6ed6b2b753998ec649da92f5ed
sha256: c0cf648cfa8bacb42ffafa51a85a886486ee832935afc2fa5da212dfef9f5720
sha512: 495baca397d5b2c884c3829e70b4928204cd711653701ab017e8f76bb5acd2c639716673d019d6f77c2b59708b53a8a9ef363cf15e12c7eb2b1ff6f380d6be62
ssdeep: 6144:AfBGxiWnoo1z+s01SbMnvPeBWOgNj/70Hr8ur2jeX:Amloo1z+s4vPsWOSEHwua6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B24E0217271C0B2E4B61A3419B89BB15A7FF93386B5C24FBB84522A8F617C4BD35353
sha3_384: d22a0dec1f2e80941cc54194b34a38f08268595c8af5ed13be166c05563d907c354e7aa50073e1130fc009b0663063c5
ep_bytes: e84b320000e989feffff8bff558bec8b
timestamp: 2013-09-16 23:35:58

Version Info:

CompanyName: Google Inc.
FileDescription: Chrome Frame renders the Web of the future in the browsers of the past. It's like strapping a rocket engine to a minivan.
FileVersion: 29.0.1547.76
InternalName: chrome_frame_helper_exe
LegalCopyright: Copyright 2012 Google Inc. All rights reserved.
OriginalFilename: chrome_frame_helper.exe
ProductName: Google Chrome Frame
ProductVersion: 29.0.1547.76
CompanyShortName: Google
ProductShortName: ChromeFrame
LastChange: 223446
Official Build: 1
Translation: 0x0409 0x04e4

Win32/Injector.ANZV also known as:

DrWebTrojan.Mods.7
MicroWorld-eScanTrojan.GenericKDZ.23250
FireEyeGeneric.mg.a79b3ef42649bc26
CAT-QuickHealTrojanspy.Zbot.8663
McAfeePWSZbot-FIO!A79B3EF42649
CylanceUnsafe
VIPRETrojan.Win32.Zbot.goo (v)
SangforTrojan.Win32.GenericKDZ.23250
K7AntiVirusTrojan ( 0055e3991 )
AlibabaTrojanSpy:Win32/Ainslot.4b51e655
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.42649b
BitDefenderThetaGen:NN.ZexaCO.34212.nu3@a4GWPuhi
CyrenW32/Trojan.MGKA-3829
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ANZV
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-64705
KasperskyTrojan-Spy.Win32.Zbot.qieh
BitDefenderTrojan.GenericKDZ.23250
NANO-AntivirusTrojan.Win32.Zbot.ciggqx
AvastSf:Zbot-E [Trj]
TencentWin32.Trojan-spy.Zbot.Lnod
Ad-AwareTrojan.GenericKDZ.23250
EmsisoftTrojan.GenericKDZ.23250 (B)
ComodoTrojWare.Win32.Agent.QELG@53m8nr
ZillyaTrojan.Zbot.Win32.209797
McAfee-GW-EditionPWSZbot-FIO!A79B3EF42649
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKDZ.23250
JiangminTrojanSpy.Zbot.etoo
AviraTR/Spy.Zbot.rhwnxe
MAXmalware (ai score=98)
Antiy-AVLTrojan/Generic.ASMalwS.4AB9C3
KingsoftWin32.Troj.Zbot.qi.(kcloud)
ArcabitTrojan.Generic.D5AD2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Ainslot.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.C205320
VBA32TScope.Malware-Cryptor.SB
ALYacTrojan.GenericKDZ.23250
MalwarebytesSpyware.ZeuS
APEXMalicious
RisingWorm.Ainslot!8.53E (CLOUD)
YandexTrojanSpy.Zbot!qs8AUhKJkVA
IkarusTrojan.Win32.Gepys
MaxSecureTrojan.Malware.7177038.susgen
FortinetW32/Injector.ANZV!tr
AVGSf:Zbot-E [Trj]
PandaTrj/Agent.JIQ
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Injector.ANZV?

Win32/Injector.ANZV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment