MavInject32.exe
Summary
Microsoft Application Virtualization Injector (32-bit) - injects DLLs into running processes. A signed Microsoft binary commonly abused for process injection.
MavInject32.exe is the 390th most commonly executed Windows program in EchoTrail's dataset, observed 20,072 times across enterprise environments. It typically runs from C:\Program Files\Common Files\microsoft shared\ClickToRun and it is most often launched by OfficeClickToRun.exe.
Behavior
Top Paths
- C:\Program Files\Common Files\microsoft shared\ClickToRun99.27%
- C:\Program Files\Microsoft Office 15\ClientX640.73%
Top Hashes (SHA256)
- 84d4c479221646130ed559a78fb278996fbc060cf87debf6e8bd2c270a7d70f273.74%
- c9e60f0e9be20953a351b12e4b0f9f861ff2b9bebae0b6e95c406f73d213cb3c6.17%
- 51085873f7dc54b043c13e70cda82cc1616c2aa89412f05a79141877f02312655.96%
- c31fb2a4037670d5af4c7c7005255943005527bf35364ad99daede18cf1794ee4.5%
- d5c7a2e5edc01b102985b9a0a49dd1f703de4d0e574a175f00a51d1fb442cd072.31%
- 22f8db51c7474092936369b2561f4384f99202670df9b950d69366add32525311.56%
- a1a44cd551a82b9696bb021da09ea7a5276db81ba28dbff5a41971459c68d3fc0.9%
- 7752e04243258ea20f42a35e7f1e555f272c1240d0ec60d04b60afbb7c1550ff0.45%
- b854417b21384b73f618851bddffc051ff7789d9ab3ac25838652400c18883d80.43%
- 265a0be0e8f44175ebdee31db80d033c3df83ae7fc753698be469a4d4ad7ed640.39%
Process Ancestry
Top Grandparents
- services.exe100%
Top Parents
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does MavInject32.exe normally do?
Used by Microsoft Application Virtualization (App-V) to inject compatibility shims into processes. Rarely seen in environments not using App-V.
When is MavInject32.exe suspicious?
Any execution outside of App-V workflows. Being called from scripts or command lines. Targeting security-sensitive processes.
How do attackers abuse MavInject32.exe?
Used as a signed proxy to inject arbitrary DLLs into processes: mavinject32.exe <PID> /INJECTRUNNING <malicious.dll>. Bypasses application whitelisting since it is a signed Microsoft binary.
Detection guidance
Alert on any execution of mavinject32.exe in environments not using App-V. Log command-line arguments to identify the target PID and injected DLL.
False positive notes
Legitimate only in App-V environments. If your organization does not use App-V, any execution is suspicious.
Ask Rocky about MavInject32.exe
Rocky answers questions about MavInject32.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.