Malware

About “Win32/Injector.XWA” infection

Malware Removal

The Win32/Injector.XWA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.XWA virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine Win32/Injector.XWA?


File Info:

crc32: 39DDBC44
md5: 9ee0059ec1711b0a3114c5db145ac189
name: 9EE0059EC1711B0A3114C5DB145AC189.mlw
sha1: b1a8b555f62e8f9721f539d1e7160696d0e8b67c
sha256: 8eb1a413673efea95460a03e3fd2210d15bdcc6089dd80b624ab379e9be3efef
sha512: 106d03c331d048d50416d6268ee25480d550a5e4fc59b1d1cf9661528acc3f5e5d6ad74b29684ee0eb7996c6159193a1b85dbd8131faa7464fb31102c35900c0
ssdeep: 6144:K4ylEA6Xn1m2JtuOlT17tkSYOO+Olrahe3mffUj:gh2Dui1cOOLlLWfm
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/Injector.XWA also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0040f1d41 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.3035
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.4056
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.83736
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojanPSW:Win32/Injector.05fea877
K7GWTrojan ( 0040f1d41 )
Cybereasonmalicious.ec1711
CyrenW32/Ransom.AO.gen!Eldorado
SymantecTrojan.Ransomlock!g8
ESET-NOD32a variant of Win32/Injector.XWA
APEXMalicious
AvastWin32:Cryptor
ClamAVWin.Ransomware.Zbot-9825963-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.4056
NANO-AntivirusTrojan.Win32.Panda.cwoeey
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
MicroWorld-eScanGen:Variant.Symmi.4056
TencentMalware.Win32.Gencirc.114b2acc
Ad-AwareGen:Variant.Symmi.4056
SophosML/PE-A + Troj/Ransom-LO
ComodoTrojWare.Win32.Injector.XWA@4ropjk
BitDefenderThetaGen:NN.ZexaF.34678.mGX@aKZts8ii
VIPREWorm.Win32.Dorkbot.i (v)
TrendMicroTSPY_RANSOM.SMKI
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.9ee0059ec1711b0a
EmsisoftGen:Variant.Symmi.4056 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.chpk
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen7
MicrosoftPWS:Win32/Zbot!CI
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Symmi.4056
AhnLab-V3Spyware/Win32.Zbot.R41309
Acronissuspicious
McAfeeRansom-AAY.gen.l
MAXmalware (ai score=87)
VBA32BScope.Malware-Cryptor.Oop
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_RANSOM.SMKI
RisingDropper.Generic!8.35E (CLOUD)
IkarusWin32.LockScreen
FortinetW32/RANSOM.AAY!tr
AVGWin32:Cryptor
Paloaltogeneric.ml

How to remove Win32/Injector.XWA?

Win32/Injector.XWA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment