Malware

About “Win32/Injector.AVVY” infection

Malware Removal

The Win32/Injector.AVVY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.AVVY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Injector.AVVY?


File Info:

name: B86DF354CF5ABC98CE4D.mlw
path: /opt/CAPEv2/storage/binaries/3540f2f7ef7b21f729937f1a8c556589bb791b98fd4d8d05a864b0e8466aa313
crc32: 81C00809
md5: b86df354cf5abc98ce4d5710d17c0815
sha1: 8d58841387176a6617b6d3ed54a7736886f41296
sha256: 3540f2f7ef7b21f729937f1a8c556589bb791b98fd4d8d05a864b0e8466aa313
sha512: d57983576249234af1d2864a8f73207990ad4e9caeee28f9415f78e97ae1e9fa20c46fc032ad7cc802b1b6ecb7aa0a24f2e7c8e59eb6d6a96587b52285fe4622
ssdeep: 192:zZpvEkGlAsojjgcWiw2X3wM3lTPh8GynKqeKoMIVLASo8vojyvgekaUlJFA8vxu:zPGlPywfM1TPh8OqeJOSo1ndu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2B23C23BFCADA91C37756700472D67B2A3A7C253142533EEA96D72FCA1AD117E08136
sha3_384: 9c659361ad96e48bd194465d28976219874e8c8b1cc7a653ba3c7a0ccc0377f2963d7e3a9c17bda6c8c18c70ad72b417
ep_bytes: 837c240e08e9f16f000029d1e8ff3800
timestamp: 2004-05-20 05:59:45

Version Info:

0: [No Data]

Win32/Injector.AVVY also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ppatre.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.b86df354cf5abc98
SkyhighBehavesLike.Win32.PWSZbot.mm
McAfeePWSZbot-FRE!B86DF354CF5A
Cylanceunsafe
ZillyaTrojan.Agent.Win32.3892725
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005b2d2f1 )
K7GWTrojan ( 005b2d2f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.byX@aSTeX9mi
VirITTrojan.Win32.Zbot.FCP
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.AVVY
APEXMalicious
TrendMicro-HouseCallTROJ_UPATRE.SM37
ClamAVWin.Trojan.Generickd-328
KasperskyTrojan-Downloader.Win32.Agent.hdyf
BitDefenderTrojan.Ppatre.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Waski-C [Cryp]
RisingDownloader.Waski!1.A489 (CLASSIC)
EmsisoftTrojan.Ppatre.Gen.1 (B)
BaiduWin32.Trojan-Downloader.Small.ce
F-SecureTrojan.TR/Patched.Gen2
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
SophosTroj/Kryptik-CF
IkarusTrojan-Spy.Zbot
JiangminTrojanDownloader.Agent.gfbt
GoogleDetected
AviraTR/Patched.Gen2
VaristW32/Injector.BUA.gen!Eldorado
Antiy-AVLTrojan/Win32.Waski.a
KingsoftWin32.HeurC.KVMH008.a
MicrosoftTrojan:Win32/Waski.A!MTB
XcitiumTrojWare.Win32.Agent.IBMG@56rzap
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmTrojan-Downloader.Win32.Agent.hdyf
GDataWin32.Trojan-Downloader.Upatre.BJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Waski.R638574
Acronissuspicious
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Suspicious
ZonerTrojan.Win32.21390
TencentTrojan-Downloader.Win32.Agent.hcq
YandexTrojan.DL.Agent!436pNekv+Sw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Injector.AVVY!tr
AVGWin32:Waski-C [Cryp]
Cybereasonmalicious.4cf5ab
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Waski.A!MTB

How to remove Win32/Injector.AVVY?

Win32/Injector.AVVY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment