Adware

Win32/Adware.HPDefender.FEJ malicious file

Malware Removal

The Win32/Adware.HPDefender.FEJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.HPDefender.FEJ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • A process attempted to delay the analysis task.
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Win32/Adware.HPDefender.FEJ?


File Info:

name: CDC7B3335FC010571B9B.mlw
path: /opt/CAPEv2/storage/binaries/1635241ae5620868e668e465c5d3a2db5342140c77eb9f6c705d2742422ae608
crc32: BE6D137F
md5: cdc7b3335fc010571b9b0b6b6fe1c3a7
sha1: b518278705a6a80c89e47c48ea68fb6ba62c8781
sha256: 1635241ae5620868e668e465c5d3a2db5342140c77eb9f6c705d2742422ae608
sha512: 4487ac0081b5e61ab39189e225050695571ccfbe0d3ba0ace94163aee0da2c4bff7ac2a846f3f042a7664a0b79970ee0bdfa1c1de3c55598e585404ff0cbb0f4
ssdeep: 3072:jo3U5b/O6N5yjkBDXagZL2bgw7J7vd0rffwoMgIgBdP8:j2U5b/O6N5yYBDX3Lygw7JLd6LxD8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DD34A12B9C49431C13B49320DBDA5D9963CFE700B214E6FB39C696D4FB80D27A21BA7
sha3_384: a115cc27daa700399b68531526484950a075cd9448e7e35588ee5adc5bca9e744434739757ecd3e9f08304e07065877c
ep_bytes: e87b050000e98efeffff558bec6a00ff
timestamp: 2019-04-17 10:04:33

Version Info:

CompanyName: Eyhaacl CASOI
LegalCopyright: © Eyhaacl CASOI. All rights reserved.
ProductName: AXOCNAOD
FileDescription: YGXI UOHOVN UDHOXR tzyykagot
Translation: 0x0409 0x04b0

Win32/Adware.HPDefender.FEJ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.GenericML.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47927363
FireEyeGeneric.mg.cdc7b3335fc01057
ZillyaAdware.HPDefender.Win32.1580
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/HPDefender.91bcb566
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.34160.iy0@aydOfjki
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.HPDefender.FEJ
TrendMicro-HouseCallTROJ_GEN.R002H0CAF22
Paloaltogeneric.ml
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderTrojan.GenericKD.47927363
NANO-AntivirusRiskware.Win32.HPDefender.fpmztt
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.Generic.Tcvv
Ad-AwareTrojan.GenericKD.47927363
EmsisoftTrojan.GenericKD.47927363 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic PUP.x
SentinelOneStatic AI – Malicious PE
SophosGeneric PUA LF (PUA)
APEXMalicious
GDataTrojan.GenericKD.47927363
JiangminTrojan.Multi.awp
MaxSecureTrojan.Malware.82199810.susgen
AviraHEUR/AGEN.1103386
Antiy-AVLTrojan/Generic.ASMalwS.2B358D5
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
AhnLab-V3Adware/Win32.HPDefender.C2693851
McAfeeRDN/Generic PUP.x
VBA32BScope.Trojan.Wacatac
MalwarebytesAdware.HPDefender
RisingTrojan.Fuerboos!8.EFC8 (CLOUD)
YandexPUA.HPDefender!KQFxBDYDQno
IkarusPUA.HPDefender
FortinetRiskware/HPDefender
AVGWin32:Adware-gen [Adw]
PandaTrj/GdSda.A

How to remove Win32/Adware.HPDefender.FEJ?

Win32/Adware.HPDefender.FEJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment