Malware

Win32/Injector.AWAO removal instruction

Malware Removal

The Win32/Injector.AWAO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.AWAO virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Win32/Injector.AWAO?


File Info:

name: FDA847071B1F8872A533.mlw
path: /opt/CAPEv2/storage/binaries/1621faeb52bfd4b126795a47b8dc379dedee5f6ce425cab7bf669944494a006b
crc32: 81C23F6C
md5: fda847071b1f8872a533035720eedf80
sha1: 1cd5572e119170234d2623e8c87d6ac34b88f6b6
sha256: 1621faeb52bfd4b126795a47b8dc379dedee5f6ce425cab7bf669944494a006b
sha512: 1205449128c7a5816d6b4c7569eddbe6b1e4142ac0c682fc233dd78c9d746354c3f67a45595ebc968fc3ac6c778aa5a7d1fca65f8b2d57c45009c132e1c7f3da
ssdeep: 6144:5bEbkNzF2obWcWXoquA4s+IYo1h5Q674JoT2PlhgDwTRpDI:ZCoz8obW5XoZA4PIYo1hGRJ6slhOwTRS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C74BF20B291C8B6E85720708D6ADA711566B87A9BB155CF33C63B3F5EB23C2017774B
sha3_384: 42b66c27ecc158b0358f79e7693a9bf3a730d59e679a5e8203167c2c9e361da1ec64791cb50dae46cea379f2f3075813
ep_bytes: e8cd620000e995feffff3b0df4274200
timestamp: 2014-01-20 19:49:34

Version Info:

0: [No Data]

Win32/Injector.AWAO also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Inject.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.fda847071b1f8872
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacGen:Variant.Graftor.128286
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Inject.ebcce425
K7GWTrojan ( 0055e3991 )
K7AntiVirusTrojan ( 0055e3991 )
ArcabitTrojan.Graftor.D1F51E
VirITTrojan.Win32.Packed.BLSN
CyrenW32/Agent.XH.gen!Eldorado
SymantecTrojan.Zbot!gen43
ESET-NOD32a variant of Win32/Injector.AWAO
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1158672
KasperskyTrojan.Win32.Inject.higy
BitDefenderGen:Variant.Graftor.128286
NANO-AntivirusTrojan.Win32.Inject.csvwuz
SUPERAntiSpywareTrojan.Agent/Gen-Luder
MicroWorld-eScanGen:Variant.Graftor.128286
AvastWin32:Trojan-gen
TencentWin32.Trojan.Inject.Egya
Ad-AwareGen:Variant.Graftor.128286
SophosMal/Generic-R + Troj/Agent-AFTP
ComodoMalware@#3oi2im1l1nnel
DrWebTrojan.Packed.25493
ZillyaTrojan.Inject.Win32.67255
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftGen:Variant.Graftor.128286 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Inject.asrg
AviraHEUR/AGEN.1210221
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.Zbot
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftPWS:Win32/Zbot!ml
ZoneAlarmTrojan.Win32.Inject.higy
GDataGen:Variant.Graftor.128286
AhnLab-V3HEUR/Fakon.apf.X1353
McAfeePWSZbot-FDR!FDA847071B1F
TACHYONTrojan/W32.Inject.365064
VBA32Trojan.Inject
RisingTrojan.Inject!8.103 (CLOUD)
YandexTrojan.Inject!qrwMFaUgG/Q
IkarusTrojan.Win32.Inject
eGambitUnsafe.AI_Score_96%
FortinetW32/Generic.AP.37830
BitDefenderThetaGen:NN.ZexaF.34212.wuZ@aq2lPQfi
AVGWin32:Trojan-gen
Cybereasonmalicious.71b1f8
PandaTrj/Genetic.gen

How to remove Win32/Injector.AWAO?

Win32/Injector.AWAO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment