Malware

Should I remove “Win32/DriverGenius.D potentially unwanted”?

Malware Removal

The Win32/DriverGenius.D potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/DriverGenius.D potentially unwanted virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/DriverGenius.D potentially unwanted?


File Info:

name: D30BBA71244A678ABCC3.mlw
path: /opt/CAPEv2/storage/binaries/60d731739bf1bbcfbf3d5eb76f5f8911268d3a84d8358314bea07807cf4ddaa4
crc32: 6F36847D
md5: d30bba71244a678abcc3834bb7c65d08
sha1: a39f7aee4f9ccce56fdbf797df1c1ca43931078f
sha256: 60d731739bf1bbcfbf3d5eb76f5f8911268d3a84d8358314bea07807cf4ddaa4
sha512: 44ba95ef04c0d3022d38d733ca17438f196f05610a43f95137bbc8d60bd941126cf2b14abbd78da35343a898dc6574902f056403444b05a448fac0efaea9db41
ssdeep: 49152:JMUDA7sqKQ55s+Pbp8LnePoC0kAVdOtcGv81uSItm7vfCXjx/2G9cv77En1:2/FKc5yLnePJ0kAdOtcGv81uSItmbCXL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8E5BE0373E58077D6B362740A7B23B5BBB57E615C35E94F27503A0E2932B429A36327
sha3_384: 2e6eaee6bbdb2e742983b27a13cb8cc6d8f47f04fa6b72379dcc70f1244c95be5e9a820b8ddb9892bd93a77c580fc595
ep_bytes: 60be00d042008dbe0040fdff5783cdff
timestamp: 2004-07-12 14:36:35

Version Info:

0: [No Data]

Win32/DriverGenius.D potentially unwanted also known as:

BkavW32.AIDetect.malware1
DrWebProgram.Unwanted.1176
MicroWorld-eScanDropped:Trojan.GenericKD.48061697
FireEyeDropped:Trojan.GenericKD.48061697
ALYacDropped:Trojan.GenericKD.48061697
ZillyaWorm.Anilogo.Win32.118
K7AntiVirusTrojan ( 000043491 )
K7GWTrojan ( 000043491 )
Cybereasonmalicious.e4f9cc
ESET-NOD32a variant of Win32/DriverGenius.D potentially unwanted
AvastWin32:Malware-gen
BitDefenderDropped:Trojan.GenericKD.48061697
Ad-AwareDropped:Trojan.GenericKD.48061697
EmsisoftDropped:Trojan.GenericKD.48061697 (B)
McAfee-GW-EditionBehavesLike.Win32.Trojan.vh
SophosMal/Generic-S
eGambitUnsafe.AI_Score_97%
AviraTR/Dropper.VB.Gen8
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.7622D5
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Generic.D2DD5D01
GDataDropped:Trojan.GenericKD.48061697
CynetMalicious (score: 99)
McAfeeRDN/Generic.dx
APEXMalicious
RisingPUA.DriverGenius!8.4D71 (RDMK:cmRtazrunfR3ge0W22y1W9q+kzcf)
YandexRiskware.Unwanted!zvNcq5GoQxs
SentinelOneStatic AI – Malicious SFX
FortinetRiskware/DriverGenius
AVGWin32:Malware-gen

How to remove Win32/DriverGenius.D potentially unwanted?

Win32/DriverGenius.D potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment