Malware

About “Win32/Injector.FVF” infection

Malware Removal

The Win32/Injector.FVF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.FVF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library

How to determine Win32/Injector.FVF?


File Info:

name: CE3FB56655FDDBB605C3.mlw
path: /opt/CAPEv2/storage/binaries/812d870d8e6edbabae75599f7fc8c6cdd783910775a9684a96c996aeec52026e
crc32: BF77A938
md5: ce3fb56655fddbb605c3621211d1a463
sha1: d1ca00cf4e6c72cc6b94b12766802f33e558494b
sha256: 812d870d8e6edbabae75599f7fc8c6cdd783910775a9684a96c996aeec52026e
sha512: 1d22bc0240c48a372481aee9787aa6d93d86791d9383e09f3359477b2143a6b7ba4856f7042ba778fe6d9a39a19d72886350d925b2f9539c73a557b7fe247d52
ssdeep: 24576:tNYd0+fn4vmXzoR579dzX+v7cUGxya8L9/sDoLW/V1CV/MAcC/2oc07wjgd9Zp+i:Efnyczo/DzW74j8SB1EM+/1D7sQJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DF4533C374858072CC1166381137D391E79AAFA01DA186CB6F6E39BDEF347A46B5CE09
sha3_384: 4b6a9a13d7dfec37805c1e7f237b7f09838955c280a374cbb9f5083c9ff583094e203c7cb3f1a1234110cef6941c3378
ep_bytes: e8fa150000e978feffff8bff558bec8b
timestamp: 2011-04-14 06:01:46

Version Info:

CompanyName: Copyright (C) 2010-2011 Marvell Semiconductor
FileDescription: Marvell Printer Status Monitor
FileVersion: 2010.304.1.17829
InternalName: printdrv
LegalCopyright: Copyright (C) 2010-2011 Marvell Semiconductor
OriginalFilename: HP1100SM
ProductName: Marvell Printer Status Monitor
ProductVersion: 2010.304.1.17829
Translation: 0x0009 0x04b0

Win32/Injector.FVF also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Titirez.iv3@IW0VNQmi
ALYacGen:Heur.Mint.Titirez.iv3@IW0VNQmi
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.34582.iv3@aW0VNQmi
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.FVF
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Heur.Mint.Titirez.iv3@IW0VNQmi
NANO-AntivirusTrojan.Win32.Zbot.kjwih
AvastSf:ShellCode-AU [Trj]
EmsisoftGen:Heur.Mint.Titirez.iv3@IW0VNQmi (B)
DrWebTrojan.Webmoner.61004
VIPREGen:Heur.Mint.Titirez.iv3@IW0VNQmi
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Mal/Inject-CEE
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.330C
VBA32TrojanSpy.SpyEyes
MalwarebytesMalware.Heuristic.1003
YandexTrojan.GenAsa!j7sqxYgrPYk
IkarusTrojan.Win32.Cidox
FortinetW32/Zbot.AAN!tr
AVGSf:ShellCode-AU [Trj]

How to remove Win32/Injector.FVF?

Win32/Injector.FVF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment