Virus

Virus:Win32/Floxif.RPX!MTB removal instruction

Malware Removal

The Virus:Win32/Floxif.RPX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Floxif.RPX!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Floxif.RPX!MTB?


File Info:

name: 0FA13E0BC61EA17D433D.mlw
path: /opt/CAPEv2/storage/binaries/34fb8fbf7c5999a53b7f7f25adb2efcbb5289d6c9c9e68e524daba9d9ebe2db0
crc32: 9ED7126D
md5: 0fa13e0bc61ea17d433d3e514ec61f97
sha1: 101f8a4fc13d647dc6a5a29fbe9bd7d8793db713
sha256: 34fb8fbf7c5999a53b7f7f25adb2efcbb5289d6c9c9e68e524daba9d9ebe2db0
sha512: 94190fd3ccbfa329fb543986be2ac9ed2c03d44751417321652d2a77ff43420d34133c5e461d0f1784f95449e0585ab5aae7db6b089678eb14604d85755af4ff
ssdeep: 3072:480J8IMILmCa3yx6oFEdgVXnFtgKuxgfxm3:4okmCaiEoFEd+Fy6xm
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T145146C256612CA7AE19200B924AE477F96AE7933135F10C3E3C45D5A2E309E1EF35F27
sha3_384: 1c720395f4905bca433f1283545f18e5a4075b05e77fbb2c3967cb07b9b43a08779f5179f45e3f304d1e71f66842011a
ep_bytes: 44000083c4088d85ccfeffff50e87733
timestamp: 2012-12-06 17:32:32

Version Info:

0: [No Data]

Virus:Win32/Floxif.RPX!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FloxLib.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Ulise.408409
ClamAVWin.Trojan.Pioneer-10014875-0
SkyhighBehavesLike.Win32.Generic.cm
McAfeeGenericRXHC-CC!0FA13E0BC61E
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
AlibabaVirus:Win32/Floxif.166b4673
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ulise.D63B59
SymantecW32.Fixflo.B
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Ulise.408409
SUPERAntiSpywareTrojan.Agent/Gen-Graftor
AvastWin32:FloxLib-A [Trj]
SophosMal/Generic-S
VIPREGen:Variant.Ulise.408409
TrendMicroTROJ_GEN.R03BC0CLO23
EmsisoftGen:Variant.Ulise.408409 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ghqns
Antiy-AVLTrojan/Win32.Wacatac.b
Kingsoftmalware.kb.b.854
MicrosoftVirus:Win32/Floxif.RPX!MTB
GDataGen:Variant.Ulise.408409
VaristW32/S-48a47791!Eldorado
AhnLab-V3Malware/Win32.RL_Generic.R259218
Acronissuspicious
ALYacGen:Variant.Ulise.408409
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0CLO23
RisingVirus.Floxif!8.614 (CLOUD)
IkarusTrojan.Agent
MaxSecureTrojan.Malware.205109546.susgen
FortinetW32/FloxLib.A!tr
AVGWin32:FloxLib-A [Trj]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Floxif.RPX!MTB?

Virus:Win32/Floxif.RPX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment