Adware

Win32/Adware.HPDefender.EFW (file analysis)

Malware Removal

The Win32/Adware.HPDefender.EFW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.HPDefender.EFW virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Adware.HPDefender.EFW?


File Info:

crc32: 92414752
md5: 1f376499b48c171df6f6fad407969d80
name: 1F376499B48C171DF6F6FAD407969D80.mlw
sha1: 2d85a9a4219f47fa17b14510c459afdbd4a06912
sha256: 62c50f5d224a09f28e9752498bb73f3b74b8b2d3b8d41f0877558c9aab5e46f0
sha512: 9b0a3beb81c691605ca2711704dd8360b5ddac5635e8256f2a203d080dbb590317a4aeac3ca488080ae2884db59397bb444e5d182fba0b0f017cba59281dce45
ssdeep: 49152:8zqNJY90S139Fb3fXUSvDqfzhWo1MO9zSMt4yTWLeM24:8zSW113zbvj8koHga4f324
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: wifxifjxjn
OriginalFilename: zchtexk
Comments: ytmsonkifl
ProductName: klqatrftcp
Translation: 0x0409 0x04b0

Win32/Adware.HPDefender.EFW also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.Hpdefender.2!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Jaik.42036
CylanceUnsafe
ZillyaAdware.Hpdefender.Win32.12
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/ICLoader.16d1a1c4
K7GWAdware ( 0053e6421 )
K7AntiVirusAdware ( 0053e6421 )
ESET-NOD32Win32/Adware.HPDefender.EFW
APEXMalicious
AvastWin32:Adware-gen [Adw]
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.Hpdefender.aaxa
BitDefenderGen:Variant.Jaik.42036
NANO-AntivirusRiskware.Win32.Hpdefender.fittyi
MicroWorld-eScanGen:Variant.Jaik.42036
TencentWin32.Adware.Hpdefender.Dzud
Ad-AwareGen:Variant.Jaik.42036
SophosGeneric PUA CN (PUA)
ComodoApplicUnwnt@#1kuuezudpz7gg
BitDefenderThetaGen:NN.ZexaF.34266.xy0@aOW!LNli
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PG621
FireEyeGeneric.mg.1f376499b48c171d
EmsisoftGen:Variant.Jaik.42036 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117983
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/Azorult!ml
ArcabitTrojan.Jaik.DA434
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.ICLoader.gen
GDataGen:Variant.Jaik.42036
AhnLab-V3PUP/Win32.HPDefender.C2745475
McAfeeICLoader
MAXmalware (ai score=99)
VBA32Adware.Hpdefender
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PG621
RisingTrojan.Generic@ML.88 (RDML:KA5EV3IvSrTUK7VPsvO/ig)
YandexPUA.Hpdefender!eXIKe5gK4ak
FortinetRiskware/HPDefender
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Win32/Adware.HPDefender.EFW?

Win32/Adware.HPDefender.EFW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment