Adware

What is “Win32/Adware.HPDefender.CVP”?

Malware Removal

The Win32/Adware.HPDefender.CVP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.HPDefender.CVP virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Adware.HPDefender.CVP?


File Info:

crc32: 75147784
md5: 9a07b64a8570bd5864cac6bbcd72c9b3
name: installer_campaign_6287.exe
sha1: 56dc7851de878337f49feccd22f8e4afddfe11d7
sha256: 99edca2d3205c4d168d470b16bec5893d322fc36034da9ca2adb89ba7c1317f5
sha512: c7a8e419df950c8c79029618a70ae4a0f9f3256cdf689e8745ddb468f458d30fb53ef378b210055ca0f219f1329a725e3a97d8e48f196437329c562c5d0cf71f
ssdeep: 6144:VpkXGh4IeWF1rBw97Z3cEtzmrGHvf6E6tOvLaEbVHRapeNgdVqER43BFDOmVGDz9:MpIPm995tCi6EEO2W9/Ngd4EMxOMK9
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Win32/Adware.HPDefender.CVP also known as:

MicroWorld-eScanGen:Variant.Graftor.451661
McAfeeICLoader
CylanceUnsafe
AegisLabAdware.Win32.Hpdefender.2!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Graftor.451661
Invinceaheuristic
F-ProtW32/S-c79620b3!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.HPDefender.CVP
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Hpdefender.gen
AlibabaAdWare:Win32/HPDefender.7f80924f
NANO-AntivirusRiskware.Win32.HPDefender.ewohqi
RisingTrojan.Generic@ML.82 (RDML:WgzXeTuJttmxAhzC+KTKyQ)
EmsisoftGen:Variant.Graftor.451661 (B)
F-SecureHeuristic.HEUR/AGEN.1004112
DrWebTrojan.MulDrop11.36622
TrendMicroTROJ_GEN.R002C0PAV20
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FortinetRiskware/HPDefender
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.9a07b64a8570bd58
SophosGeneric PUA ID (PUA)
CyrenW32/S-c79620b3!Eldorado
AviraHEUR/AGEN.1017877
MAXmalware (ai score=96)
Endgamemalicious (high confidence)
ArcabitTrojan.Mikey.D121A7
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Hpdefender.gen
MicrosoftTrojan:Win32/Detplock
Acronissuspicious
VBA32Adware.Hpdefender
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PAV20
TencentWin32.Trojan.Graftor.Hsih
YandexPUA.HPDefender!
SentinelOneDFI – Malicious PE
GDataGen:Variant.Mikey.74151
BitDefenderThetaGen:NN.ZexaE.34084.nC0@ayoRa5ii
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.a8570b
AvastWin32:Adware-gen [Adw]
Qihoo-360Win32/Virus.Adware.f13

How to remove Win32/Adware.HPDefender.CVP?

Win32/Adware.HPDefender.CVP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment