Virus

Virus:Win32/Floxif.RPX!MTB removal guide

Malware Removal

The Virus:Win32/Floxif.RPX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Floxif.RPX!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Floxif.RPX!MTB?


File Info:

name: 610FDF3322B003B84D13.mlw
path: /opt/CAPEv2/storage/binaries/1471a5a6c8e504284ef3e547c722054bb2ac17520045e0c4d7ba49d76543b8cb
crc32: 07A8A0CB
md5: 610fdf3322b003b84d13a5344364418f
sha1: 3a05b5d01dbf9c0cb212187a671196cd776338da
sha256: 1471a5a6c8e504284ef3e547c722054bb2ac17520045e0c4d7ba49d76543b8cb
sha512: aba8427830e2766991b923828ac3e969cb452d3d30fe00e60ccc2c966e680dc007bae952c49de40ea079a6944f5542efcf6ad079efc25519e3c72edff845c77a
ssdeep: 3072:480J8IMIfIedMl8/tkoFEdgVXnFuCRogfxm3:4ogIedMaVkoFEd+FDdxm
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1A7146B257692C67AE59200B629AE477F46697933031F10C3E3C45D6A2E309E2FB35F27
sha3_384: 3fe75c98cd7cd36728a41a660b06245f1ac22621e4ece2360ba0850549a6a7bd4f8f35a9e670bf489ebecf40244c2039
ep_bytes: 44000083c4088d85ccfeffff50e87733
timestamp: 2012-12-06 17:32:32

Version Info:

0: [No Data]

Virus:Win32/Floxif.RPX!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Ulise.408409
SkyhighBehavesLike.Win32.Generic.cm
McAfeeGenericRXHC-CC!610FDF3322B0
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
ArcabitTrojan.Ulise.D63B59
SymantecW32.Fixflo.B
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Pioneer-10014875-0
BitDefenderGen:Variant.Ulise.408409
SUPERAntiSpywareTrojan.Agent/Gen-Graftor
AvastWin32:FloxLib-A [Trj]
SophosGeneric ML PUA (PUA)
VIPREGen:Variant.Ulise.408409
TrendMicroTROJ_GEN.R03BC0CAQ24
FireEyeGeneric.mg.610fdf3322b003b8
EmsisoftGen:Variant.Ulise.408409 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.ghqns
VaristW32/S-48a47791!Eldorado
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Wacatac.b
Kingsoftmalware.kb.b.816
MicrosoftVirus:Win32/Floxif.RPX!MTB
GDataGen:Variant.Ulise.408409
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R259218
ALYacGen:Variant.Ulise.408409
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0CAQ24
IkarusTrojan.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/FloxLib.A!tr
AVGWin32:FloxLib-A [Trj]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Floxif.RPX!MTB?

Virus:Win32/Floxif.RPX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment