Crack

Win32:Patched-AWW [Trj] removal

Malware Removal

The Win32:Patched-AWW [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Patched-AWW [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:Patched-AWW [Trj]?


File Info:

name: D6D91E118BC00AF4D44A.mlw
path: /opt/CAPEv2/storage/binaries/d2424800f78b2aad71bbddbe51590605f062c0dda0d2053179fb05fe50aa0af7
crc32: 4EA85807
md5: d6d91e118bc00af4d44ab7f9f12f231e
sha1: d4a1c90ab8347df082b6de03fd9834af93280229
sha256: d2424800f78b2aad71bbddbe51590605f062c0dda0d2053179fb05fe50aa0af7
sha512: 83f099788e53eee5ae84966725b6ff68c4864447fd97291844c001ada6e814e9665230235dcf827a91374e8c517b6c58c17bdd3fa05e44631839137953202ba4
ssdeep: 12288:nCeHUQvmQiT3uTjBTDzP0LLDYUNh03CWbPXc4Tq:Ce0PTwTPP0bYUH031bfc4Tq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B194D112B2D3C131E15726B40AA68AB50EBAFC7571F5A94E7FCB0B7A8B143D0D225335
sha3_384: f78eca196ebceb10f2d2b80b4bb68ea07e53fb8ad505bf95f849d415fe97b5251943ae3372ca8e8f75ca7fee8d904557
ep_bytes: e8c1e9ffffe989feffff578bc683e00f
timestamp: 2012-04-04 01:56:45

Version Info:

0: [No Data]

Win32:Patched-AWW [Trj] also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Doina.63686
ALYacGen:Variant.Doina.63686
MalwarebytesMalware.AI.1027760482
K7AntiVirusTrojan ( 005ab4bf1 )
K7GWTrojan ( 005ab4bf1 )
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW32/SoftPulse.CR.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.NKM
APEXMalicious
KasperskyVHO:Trojan-Dropper.Win32.Convagent.gen
BitDefenderGen:Variant.Doina.63686
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Patched-AWW [Trj]
TencentMalware.Win32.Gencirc.10bf20ec
EmsisoftGen:Variant.Doina.63686 (B)
DrWebWin32.Beetle.2
VIPREGen:Variant.Doina.63686
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.d6d91e118bc00af4
IkarusTrojan.Win32.Krypt
GDataGen:Variant.Doina.63686
JiangminBackdoor.Convagent.mu
GoogleDetected
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.GenKryptik
ArcabitTrojan.Doina.DF8C6
ZoneAlarmHEUR:Trojan-Dropper.Win32.Agent.gen
MicrosoftTrojan:Win32/Convagent.AI!MTB
AhnLab-V3Malware/Win.Generic.C5481402
VBA32BScope.TrojanDownloader.Emotet
RisingTrojan.Generic@AI.100 (RDML:SXEACztpnxiHZZqEUe6YUA)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Patched.IP!tr
BitDefenderThetaAI:Packer.B141492D1F
AVGWin32:Patched-AWW [Trj]
Cybereasonmalicious.ab8347

How to remove Win32:Patched-AWW [Trj]?

Win32:Patched-AWW [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment