Malware

What is “Win32/Injector.DWAW”?

Malware Removal

The Win32/Injector.DWAW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DWAW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine Win32/Injector.DWAW?


File Info:

crc32: 376D3F24
md5: 9fb59f799bd06dbd421c66a6df40ee99
name: 9FB59F799BD06DBD421C66A6DF40EE99.mlw
sha1: 054dea549e7b08e6ba67b0497fcbce7504247252
sha256: 02f3613f0a099b84334e0018d365e9672bf4f174eaae56eaf0725c42f7616e07
sha512: a7aa7b315b0645a48bdedfbae8bc1a5b250cb70866705362fb5f3cf406493bede0bf651619b7acbaba0596f3e03a1a87776c5a0bee537ded5c5bb13b891d9d4b
ssdeep: 3072:+EeV2yW42jvUOy+2R8VszrfKZ0IryBVTyrnL+6kvx+L7u52Cv0W5TKF6Fv+9Lfz:+5Y42jsOyN3LsrqqnLwO7IbBgz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: BITTORTEnt Inc.
InternalName: Bekymringen5
FileVersion: 9.08.0002
CompanyName: KREe RiHe
LegalTrademarks: STEllAr INfORmation Systems Ltd
Comments: UVNc bVb
ProductName: VODAFONe
ProductVersion: 9.08.0002
FileDescription: GETCOmposer.org
OriginalFilename: Bekymringen5.exe

Win32/Injector.DWAW also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005280331 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.22065
CynetMalicious (score: 100)
ALYacGen:Heur.PonyStealer.nm0@cKkw6dei
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.49590
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Androm.ali2000017
K7GWTrojan ( 005280331 )
Cybereasonmalicious.99bd06
CyrenW32/Fareit.DG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DWAW
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packer.VbPack-0-6334882-0
KasperskyBackdoor.Win32.Androm.pckr
BitDefenderGen:Heur.PonyStealer.nm0@cKkw6dei
NANO-AntivirusTrojan.Win32.Androm.eyiwtg
MicroWorld-eScanGen:Heur.PonyStealer.nm0@cKkw6dei
TencentWin32.Backdoor.Androm.Hyjt
Ad-AwareGen:Heur.PonyStealer.nm0@cKkw6dei
SophosMal/Generic-R + Mal/FareitVB-L
ComodoMalware@#3hwptc4iii35p
BitDefenderThetaGen:NN.ZevbaF.34266.nm0@aKkw6dei
TrendMicroTSPY_HPLOKI.SMVB1
McAfee-GW-EditionFareit-FKY!9FB59F799BD0
FireEyeGeneric.mg.9fb59f799bd06dbd
EmsisoftGen:Heur.PonyStealer.nm0@cKkw6dei (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1128743
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.PonyStealer.E0BAC4
GDataGen:Heur.PonyStealer.nm0@cKkw6dei
AhnLab-V3Win-Trojan/VBKrypt.RP02.X1828
McAfeeFareit-FKY!9FB59F799BD0
MAXmalware (ai score=89)
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTSPY_HPLOKI.SMVB1
YandexTrojan.GenAsa!ITSlK8eUJWE
IkarusTrojan.VB.Crypt
FortinetW32/Injector.ECCL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Injector.DWAW?

Win32/Injector.DWAW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment