Adware

Win32/Adware.HPDefender.ENA malicious file

Malware Removal

The Win32/Adware.HPDefender.ENA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.HPDefender.ENA virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Win32/Adware.HPDefender.ENA?


File Info:

name: 0034BEFB1D31F88E1F11.mlw
path: /opt/CAPEv2/storage/binaries/ef92348b31abad47c8c452ff346cc2a122e537e1cb490d7882c20bd5b2334961
crc32: 90DFB8D8
md5: 0034befb1d31f88e1f112df55a627d5d
sha1: cee8a65efd2b9a6a20d8b13419d00ca76e0b5145
sha256: ef92348b31abad47c8c452ff346cc2a122e537e1cb490d7882c20bd5b2334961
sha512: 0b44740586888922cb2a6a14a8a48a68a6c561d90691a4aeff5782c3d7828735f6c9f8198c843e95dfe964efdc31dad3c2f5d6302829d8f27f44505cfa06918c
ssdeep: 3072:E2GfAZl4GSVx86ozIZR64+NsA3lcdmtBZkHSNhw3eHKiwU0zw:EjfAZl4KaRQNsNm3Le6Ko0z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AEF33B2534C58031E2B98A7AD8FDDA75951CB9350F650CDFB3958B2E3B304E146B2E2B
sha3_384: b3f182e27a2171384d4f7cb9e28bd93ce7dd19525a2a5efee975ed5a3bce8704e625a50d69b52e76b5e2a1960a54972b
ep_bytes: e850050000e98efeffff558bec6a00ff
timestamp: 2018-11-29 09:30:52

Version Info:

ProductName: IQLITV Vasomfeeha Qjyup
ProductVersion: 3.15.255.32864
LegalCopyright: Dekixuw UJRIOMF. All rights reserved.
CompanyName: Dekixuw UJRIOMF
Translation: 0x0409 0x04b0

Win32/Adware.HPDefender.ENA also known as:

LionicRiskware.Win32.Symmi.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Symmi.90089
FireEyeGeneric.mg.0034befb1d31f88e
McAfeeArtemis!0034BEFB1D31
CylanceUnsafe
ZillyaAdware.Hpdefender.Win32.17
SangforAdware.Win32.Symmi.90089
K7AntiVirusAdware ( 0054299f1 )
AlibabaAdWare:Win32/HPDefender.1f8993bf
K7GWAdware ( 0054299f1 )
Cybereasonmalicious.b1d31f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.HPDefender.ENA
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Adware.Symmi.90089
NANO-AntivirusRiskware.Win32.HPDefender.fkssgh
AvastFileRepMalware
TencentWin32.Risk.Adware.Bds
Ad-AwareGen:Variant.Adware.Symmi.90089
EmsisoftGen:Variant.Adware.Symmi.90089 (B)
ComodoApplicUnwnt@#g834mqchk2ys
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.RunBooster.ch
SophosGeneric PUA MO (PUA)
IkarusPUA.HPDefender
GDataGen:Variant.Adware.Symmi.90089
AviraADWARE/HPDefender.kphae
Antiy-AVLTrojan/Generic.ASMalwS.29B4613
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ViRobotAdware.Symmi.166400
MicrosoftTrojan:Win32/Occamy.CEF
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.HPDefender.C2889362
BitDefenderThetaGen:NN.ZexaE.34084.ky0@aOfWMldi
ALYacGen:Variant.Adware.Symmi.90089
TrendMicro-HouseCallTROJ_GEN.R002H0CJH21
RisingTrojan.Generic@ML.100 (RDML:IeFN2sUJZiU1047gl01DoQ)
YandexPUA.HPDefender!9d24wqqaIG4
FortinetRiskware/HPDefender
AVGFileRepMalware
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/Adware.HPDefender.ENA?

Win32/Adware.HPDefender.ENA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment