Adware

Should I remove “Win32/Adware.HPDefender.EBG”?

Malware Removal

The Win32/Adware.HPDefender.EBG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.HPDefender.EBG virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Win32/Adware.HPDefender.EBG?


File Info:

name: CD2952FA263BAA94F794.mlw
path: /opt/CAPEv2/storage/binaries/abdc9946d65ce346a540578c19d5635998d4bf98c0b49127b737f66be1aa03e4
crc32: AB1E55F0
md5: cd2952fa263baa94f7943f3a5ed2559f
sha1: 773573cca3960c8437b69ba4c5e388af713771f3
sha256: abdc9946d65ce346a540578c19d5635998d4bf98c0b49127b737f66be1aa03e4
sha512: 9628c722cd1a6f39f95eea48c656514d939ddcdf0abfd186230282e1f1138fcfe650fe17f2f66c8306628472337220e37ff0b47bca058fa1667f3fc71e9f0a95
ssdeep: 12288:A9EN6Bi8Gr1wkcAFjHket5PW8aDW8W8W8WqkPYhyHVUuyp:1N0kgkauy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BDA4FA343DEF9039E173EE715FE8B697DD6EF7322A09545F2181030B4622981EE51A3A
sha3_384: e926da38c80995c3f7182303fc2c18896e92c77fdf659ff3904e1f5d7e958ccf3d917c3b029997bf20c5aaf2bcede530
ep_bytes: e81a040000e98efeffff558bec6a00ff
timestamp: 2018-08-21 12:05:50

Version Info:

FileDescription: nkoyn yvtu ywaam
InternalName: Mohfyo
CompanyName: gayzifabo
ProductName: Vqueqfaetf
Translation: 0x0409 0x04b0

Win32/Adware.HPDefender.EBG also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.Hpdefender.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.37120242
FireEyeGeneric.mg.cd2952fa263baa94
ALYacTrojan.GenericKD.37120242
CylanceUnsafe
SangforPUP.Win32.HPDefender.EBG
K7AntiVirusAdware ( 0053b6771 )
AlibabaAdWare:Win32/Hpdefender.92f898f0
K7GWAdware ( 0053b6771 )
Cybereasonmalicious.ca3960
BitDefenderThetaGen:NN.ZexaF.34294.By0@amBR32fi
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Adware.HPDefender.EBG
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.Hpdefender.aasp
BitDefenderTrojan.GenericKD.37120242
NANO-AntivirusRiskware.Win32.HPDefender.fhbmdl
AvastFileRepMalware
TencentWin32.Adware.Hpdefender.Szbl
Ad-AwareTrojan.GenericKD.37120242
SophosGeneric PUA HH (PUA)
ComodoMalware@#3rz3fjfn9v0hx
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PKN21
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
EmsisoftTrojan.GenericKD.37120242 (B)
IkarusPUA.HPDefender
GDataTrojan.GenericKD.37120242
AviraHEUR/AGEN.1103337
Antiy-AVLTrojan/Generic.ASMalwS.34C4DC1
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win32.Occamy.sa
MicrosoftTrojan:Win32/Occamy.CAB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2687304
Acronissuspicious
McAfeeGenericRXGD-XH!CD2952FA263B
VBA32BScope.Adware.Hpdefender
MalwarebytesMachineLearning/Anomalous.100%
APEXMalicious
RisingTrojan.Generic@ML.96 (RDMK:3gTozs8R5VGNP/+6HQeg8g)
YandexPUA.Hpdefender!kT4/FRpWEWQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/PUP_XFQ
WebrootW32.Malware.Gen
AVGFileRepMalware
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/Adware.HPDefender.EBG?

Win32/Adware.HPDefender.EBG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment