Adware

Win32/Adware.HPDefender.EXS (file analysis)

Malware Removal

The Win32/Adware.HPDefender.EXS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.HPDefender.EXS virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Win32/Adware.HPDefender.EXS?


File Info:

name: 24EE5EFD00086FDA97E4.mlw
path: /opt/CAPEv2/storage/binaries/104b1dbb558a75150421bbeac57899697b2c03ab6cae297dff128b23172a29f2
crc32: 67EFA910
md5: 24ee5efd00086fda97e4122b8615d384
sha1: 2fe533519a3dadd64f796931257c1068cfa0c96b
sha256: 104b1dbb558a75150421bbeac57899697b2c03ab6cae297dff128b23172a29f2
sha512: e8806bb853f544e668a1178d1bf13256fee52315da817fb73a19440b8c6d1d018871e05b51f5a5e3ab43af9fd93cac773a5dd739ae1025bd49ee0c8e5a08b057
ssdeep: 6144:bHQDK6DyyyCAOKhdmaAJEqJl+h9nLQak:nop34uaAWil+7nEak
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16864CF2170D288B3E1B349341968AAE0597DF9710F254A7F33E85A2D1F785D27A21FB3
sha3_384: cab35c881792f7bbabd94230cf0744a9b876f73da695052634cfc55685f3b7acc03470a5b727aa32877a030ffc10feb6
ep_bytes: e8f0060000e98efeffffff25c8b14100
timestamp: 2019-02-20 09:36:39

Version Info:

ProductName: Aobjuurit YLFOEHPOEF UOJGIA
InternalName: HUZALF
FileVersion: 4.18.48.56234
LegalCopyright: Kyyzcifiez Aadtof. All rights reserved.
ProductVersion: 4.18.48.56234
FileDescription: KBIRTE yndua
Translation: 0x0409 0x04b0

Win32/Adware.HPDefender.EXS also known as:

BkavW32.AIDetect.malware2
LionicRiskware.Win32.Hpdefender.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38125785
FireEyeGeneric.mg.24ee5efd00086fda
McAfeeArtemis!24EE5EFD0008
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 005697901 )
AlibabaAdWare:Win32/HPDefender.9fd07959
K7GWAdware ( 005697901 )
Cybereasonmalicious.19a3da
BitDefenderThetaGen:NN.ZexaF.34062.sC0@aeI9dDbi
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Adware.HPDefender.EXS
TrendMicro-HouseCallTROJ_GEN.R002C0OKQ21
Paloaltogeneric.ml
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderTrojan.GenericKD.38125785
NANO-AntivirusRiskware.Win32.HPDefender.fninav
AvastFileRepMalware
TencentWin32.Risk.Adware.Hsta
Ad-AwareTrojan.GenericKD.38125785
EmsisoftTrojan.GenericKD.38125785 (B)
ComodoApplicUnwnt@#2dumot58c56hg
DrWebAdware.HPDefender.11
ZillyaAdware.Hpdefender.Win32.6
TrendMicroTROJ_GEN.R002C0OKQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SentinelOneStatic AI – Malicious PE
SophosGeneric PUA CP (PUA)
APEXMalicious
GDataTrojan.GenericKD.38125785
WebrootW32.Adware.Gen
AviraADWARE/HPDefender.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.2AA6ECD
GridinsoftRansom.Win32.Occamy.sa
ArcabitTrojan.Generic.D245C0D9
ViRobotAdware.Hpdefender.310784.D
MicrosoftTrojan:Win32/Occamy.C10
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.HPDefender.C3042931
VBA32BScope.Trojan.Occamy
ALYacTrojan.GenericKD.38125785
MAXmalware (ai score=99)
MalwarebytesMachineLearning/Anomalous.100%
RisingTrojan.Generic@ML.99 (RDMK:xBBb180BsBv2w//gM0teSw)
YandexPUA.HPDefender!TlYIWcAjmJk
IkarusPUA.HPDefender
FortinetRiskware/HPDefender
AVGFileRepMalware
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Adware.HPDefender.EXS?

Win32/Adware.HPDefender.EXS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment