Malware

About “W32.PoliPos” infection

Malware Removal

The W32.PoliPos is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32.PoliPos virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine W32.PoliPos?


File Info:

name: C3B5567115B452E86A0C.mlw
path: /opt/CAPEv2/storage/binaries/088633480ed66c8d20ca41d75067af3fc7616e921e808f2bcb9d6921e1667b72
crc32: F14218DB
md5: c3b5567115b452e86a0c02d6e64f6935
sha1: 89487b1e5e13e2b749475636973b3f43e79bdf8e
sha256: 088633480ed66c8d20ca41d75067af3fc7616e921e808f2bcb9d6921e1667b72
sha512: b523e459d434cf051fdb66264f064f3a408d409be82d88f50a8bb91d0b551fb89dcbf8476f7c55e0321444c506492698cbc3b52dee21159ca7faaf0c24bb47c8
ssdeep: 6144:s8aKcrONaV2BHzDrB7b5dU14Uf797SNIbVRGAw2+8e9KZPY88NAR3xSKnB5PZ:s8YrOyCzpX5dS7cuDGH2+8xm88Y3cKvx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D74C7219E10603BEC6684B52D6AB766951D1E362F81EC0B77D1BB45B630293F6F031F
sha3_384: c20a8370aae1d2685d46450e88e5858702388a38b3c8a416fe26812eb5d5f3805312815094c188a6747f9b12cea11356
ep_bytes: 68ac414000e8eeffffff000040000000
timestamp: 2012-03-26 04:57:06

Version Info:

Translation: 0x0409 0x04b0

W32.PoliPos also known as:

BkavW32.Polip.PE
AVGWin32:Polipos
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Polip.A
FireEyeGeneric.mg.c3b5567115b452e8
CAT-QuickHealW32.PoliPos
SkyhighBehavesLike.Win32.VBObfus.fh
McAfeeW32/Autorun.worm.ru
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPREWin32.Polip.A
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
BitDefenderThetaAI:FileInfector.C262A47F0D
VirITWin32.Polip.A
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/Polip
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Polipos
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyP2P-Worm.Win32.Polip.a
BitDefenderWin32.Polip.A
NANO-AntivirusTrojan.Win32.VB.rilpo
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
TencentWorm.Win32.Vobfus.n
EmsisoftWin32.Polip.A (B)
BaiduWin32.Virus.Polip.a
F-SecureTrojan.TR/VB.Agent.ABYP
DrWebWin32.Polipos
TrendMicroPE_POLIP.A
Trapminemalicious.moderate.ml.score
SophosW32/Polipos-A
IkarusWorm.Win32.Vobfus
JiangminWorm/P2P.Polip.a
VaristW32/Polip.A
AviraTR/VB.Agent.ABYP
Antiy-AVLVirus/Win32.Expiro.rsrc
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.gen!S
XcitiumP2PWorm.Win32.Polip.A@1fnufq
ArcabitWin32.Polip.A
ViRobotWin32.Polip.Gen.A
ZoneAlarmP2P-Worm.Win32.Polip.a
GDataWin32.Polip.A
GoogleDetected
AhnLab-V3Win32/Polip
Acronissuspicious
VBA32BScope.Trojan.VB.Onechki
ALYacWin32.Polip.A
TACHYONVirus/W32.Polip
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallPE_POLIP.A
RisingWorm.VobfusEx!1.99DB (CLASSIC)
YandexTrojan.GenAsa!JGqZDhIXldQ
MAXmalware (ai score=84)
MaxSecureVirus.Polip.A
FortinetW32/VBKrypt.C!tr
ZonerVirus.Win32.Polip
DeepInstinctMALICIOUS

How to remove W32.PoliPos?

W32.PoliPos removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment