Threat Database Trojans Trojan-Spy.Win32.aiw

Trojan-Spy.Win32.aiw

By SpideyMan in Trojans

Threat Scorecard

Popularity Rank: 22,131
Threat Level: 90 % (High)
Infected Computers: 3,635
First Seen: December 27, 2011
Last Seen: December 8, 2025
OS(es) Affected: Windows

Trojan-Spy.Win32.aiw is a nonexistent Trojan which is supposedly detected by rogue security programs that urges you to buy bogus software to allegedly remove the Trojan. Trojan-Spy.Win32.aiw can not be removed because it is simply unreal. Trojan-Spy.Win32.Banker.aiw is just a name that occurs on false pop-up warning messages. If clicked upon, they divert the affected web browser to defender-review.com or similar website and ask you to purchase some malicious security software such as Personal Defender 2009. Select a genuine and effective anti-malware tool to delete Trojan-Spy.Win32.aiw.

Analysis Report

General information

Family Name: Trojan.Kryptik.BFNA
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 52fd22c67ae369ba876bc8978112bb88
SHA1: c42928dd8b88dfb65409183c0798bc004305081e
SHA256: A3E221AC342D27C54893417B7AA9AA5E554016C0FE05479BA195774F84829FCA
File Size: 585.22 KB, 585216 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • packed
  • x86

Block Information

Total Blocks: 484
Potentially Malicious Blocks: 4
Whitelisted Blocks: 476
Unknown Blocks: 4

Visual Map

? x ? x x x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 1 1 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 2 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 1 0 0 1 1 0 1 0 0 0 0 0 1 0 0 0 0 1 1 0 0 0 1 0 0 0 1 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...