Crack

Win32:Patched-AWW [Trj] removal tips

Malware Removal

The Win32:Patched-AWW [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Patched-AWW [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:Patched-AWW [Trj]?


File Info:

name: 75D81E49F77A443F3DC2.mlw
path: /opt/CAPEv2/storage/binaries/e6db2034ec0b4cb0dd49747502362bfc380262ffbd4241713ce09075e1ad3075
crc32: B5FB9319
md5: 75d81e49f77a443f3dc2b0d13283a92f
sha1: 09d3e3e660405de25e8d4bbac7615753043c2d83
sha256: e6db2034ec0b4cb0dd49747502362bfc380262ffbd4241713ce09075e1ad3075
sha512: 9dfbc2678f90914550074c7e8f2130bc1d37dd3d8d8efc39d00ab19a06c7a1921007930a5ead352a6888142cda336e99a8c60137a2e2398ca39a63e6b67e5bd8
ssdeep: 12288:lspIgxov6JwoPJn0iXaUoBW7DNTCG7F/ziwl+edRQBAWBydWpX:1KbPN0iKUoB0Tf7diY+mWcdWp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6C4AF3262946032D6B210B3F965C2307E7DA1186F2484B747D49A2E3E7C996BBF7347
sha3_384: 64c6a5a6610282e2fb8fd975ff2a106937718e8b1f4ac292986e5f4efb47ec83f3f74e4abfb4f9bff3fd8baaf5f5e2ae
ep_bytes: e8e2bc0000e979feffff8bff558bec8b
timestamp: 2013-08-20 11:18:53

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
FileVersion: 11.0.61030.0
InternalName: setup
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFilename: vcredist_x64.exe
ProductName: Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
ProductVersion: 11.0.61030.0
Translation: 0x0409 0x04e4

Win32:Patched-AWW [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Emotet.5
FireEyeGeneric.mg.75d81e49f77a443f
SkyhighBehavesLike.Win32.Generic.hc
Cylanceunsafe
VIPREGen:Heur.Emotet.5
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ab4bf1 )
K7GWTrojan ( 005ab4bf1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Patched.NKM
APEXMalicious
CynetMalicious (score: 100)
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Heur.Emotet.5
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Patched-AWW [Trj]
TencentTrojan.Win32.Pathced_ya.16001052
EmsisoftGen:Heur.Emotet.5 (B)
F-SecureTrojan.TR/Patched.Gen
DrWebWin32.Beetle.2
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.Patched
GoogleDetected
AviraTR/Patched.Gen
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Emotet.5
ZoneAlarmVirus.Win32.Senoval.a
GDataGen:Heur.Emotet.5
VaristW32/Patched.GQ1.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.C5486871
BitDefenderThetaAI:Packer.2122E8AE1E
ALYacGen:Heur.Emotet.5
VBA32BScope.TrojanDownloader.Emotet
PandaTrj/Genetic.gen
FortinetW32/Patched.IP!tr
AVGWin32:Patched-AWW [Trj]
Cybereasonmalicious.660405

How to remove Win32:Patched-AWW [Trj]?

Win32:Patched-AWW [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment