Malware

Win32/Injector.PBO malicious file

Malware Removal

The Win32/Injector.PBO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.PBO virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Win32/Injector.PBO?


File Info:

name: B514563684299521FA33.mlw
path: /opt/CAPEv2/storage/binaries/a50150acec9773f928412ca0b22c697a110e0f161534d74235dc8bfc099a2a9f
crc32: 5F024F5F
md5: b514563684299521fa332e133b266318
sha1: c09078611c5260301995de10a02e4bf273f8d4ec
sha256: a50150acec9773f928412ca0b22c697a110e0f161534d74235dc8bfc099a2a9f
sha512: ec196da20c4eac999e29e0a0d55f2019af46434af8313c44b7cecb73e8a8b131f264a8a229b6a8f18f6d441aa04d7d842a530454f1b077f4819c0b3584659d0f
ssdeep: 3072:TkLWOoYLKXdywKFYD+4om8gfnd6ePwCShf0ZUhwB/ulpww0wjBf4Z3:fVSK0Y+zmT/UuwCS5Bvc3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DBF3029630C6746EED0590B40A07DBFD133A70E3298DBBA9DFE455816C2EC324959A3F
sha3_384: 81fcc9ec18310fd238d18dbc2ced222979e208309e31da781aa7d66e9028178f1ab8bc578b6ca2d02c3ae35071e17f40
ep_bytes: 5589e583ec08c7042402000000ff151c
timestamp: 2004-09-26 16:22:09

Version Info:

0: [No Data]

Win32/Injector.PBO also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Avalod.a!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.359
MicroWorld-eScanGen:Trojan.ProcessHijack.jyX@aC2pzae
FireEyeGeneric.mg.b514563684299521
ALYacGen:Trojan.ProcessHijack.jyX@aC2pzae
CylanceUnsafe
ZillyaDownloader.Avalod.Win32.9422
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00372c441 )
AlibabaVirTool:Win32/CeeInject.50cabbaf
K7GWTrojan ( 00372c441 )
Cybereasonmalicious.684299
BitDefenderThetaAI:Packer.9112FAEB1E
VirITTrojan.Win32.DownLoad3.NV
CyrenW32/CeeInject.AK.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.PBO
TrendMicro-HouseCallWORM_AUTORUN.GUN
Paloaltogeneric.ml
ClamAVWin.Downloader.Sinowal-9849406-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.ProcessHijack.jyX@aC2pzae
NANO-AntivirusTrojan.Win32.DownLoad3.ithjxr
SUPERAntiSpywareTrojan.Agent/Gen-CeeInject
AvastWin32:Kryptik-IDX [Trj]
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareGen:Trojan.ProcessHijack.jyX@aC2pzae
ComodoMalware@#abt9m03pwslt
VIPRETrojan.Win32.Generic!BT
TrendMicroWORM_AUTORUN.GUN
McAfee-GW-EditionBehavesLike.Win32.ZBot.cc
EmsisoftGen:Trojan.ProcessHijack.jyX@aC2pzae (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.ProcessHijack.jyX@aC2pzae
JiangminTrojanDownloader.Avalod.lbf
MaxSecureTrojan.Malware.7164915.susgen
AviraTR/Buzus.44589745
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Avalod
ArcabitTrojan.ProcessHijack.E27E73
ViRobotTrojan.Win32.A.Downloader.87040.AU
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/CeeInject.CY
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Avalod.R21521
Acronissuspicious
McAfeePWS-Zbot.gen.rz
VBA32Malware-Cryptor.Inject.gen
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
TencentMalware.Win32.Gencirc.114bdbbb
YandexTrojan.GenAsa!/qIO1VQJfdM
IkarusTrojan-Downloader.Win32.Avalod
eGambitGeneric.Malware
FortinetW32/Injector.OEC!tr
WebrootW32.Trojan.Gen
AVGWin32:Kryptik-IDX [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Injector.PBO?

Win32/Injector.PBO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment