Malware

What is “Win32/GenCBL.ACH”?

Malware Removal

The Win32/GenCBL.ACH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenCBL.ACH virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Sanskrit
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32/GenCBL.ACH?


File Info:

crc32: C182485C
md5: f8ef4d5aab53a64cb56ee89ac55b122b
name: F8EF4D5AAB53A64CB56EE89AC55B122B.mlw
sha1: 05987adf782b26615d6c55276f709525af9d796b
sha256: 34b09f16fa6e9789bda97d9bd512ac7f49e235982db9d65109a4078ab3567bcf
sha512: 50169937e1f4d6a4a0ca5c9e4f2b71ac5f73bb7c274a5db3a91b47dbfcbf551c78c677575e8478743351ad93f3e3e39e55bbcbdf3ce66fb974f3160e06bcdef5
ssdeep: 98304:Q/F+obEZnhIXA0S+4OF+whJ4f1j/nC5HvKPGsUGCmIQUZNJ01Ce8n:Q0gEZnyXA0NHO/nC5PEGshHIVNJ01
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: RSA Inc 2020
Assembly Version: 2.51.14.3
InternalName: Umbonal.exe
FileVersion: 1.2.3.1
CompanyName: RSA Inc
LegalTrademarks: RSA Inc
Comments: Add-On Manager Tool
ProductName: Add-On Manager Client
ProductVersion: 1.2.3.1
FileDescription: Add-On Manager
OriginalFilename: Umbonal.exe

Win32/GenCBL.ACH also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.33898
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.36480365
CylanceUnsafe
SangforVirus_Suspicious.Win32.Sality.ae
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojanSpy:Win32/Stealer.75ea1bf0
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f782b2
CyrenW32/Trojan.ZAEB-7554
ESET-NOD32a variant of Win32/GenCBL.ACH
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.RedLine-9831542-0
KasperskyTrojan-Spy.Win32.Stealer.xvt
BitDefenderTrojan.GenericKD.36480365
MicroWorld-eScanTrojan.GenericKD.36480365
TencentWin32.Trojan.Falsesign.Egol
Ad-AwareTrojan.GenericKD.36480365
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34608.@Z1@aa4ZjUlO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.f8ef4d5aab53a64c
EmsisoftTrojan.GenericKD.36480365 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.RedLineSteal.nphvp
KingsoftWin32.Troj.Stealer.x.(kcloud)
MicrosoftVirTool:MSIL/SharpStay
GridinsoftTrojan.Heur!.01210221
ArcabitTrojan.Generic.D22CA56D
AegisLabTrojan.Win32.Stealer.l!c
GDataTrojan.GenericKD.36480365
McAfeeArtemis!F8EF4D5AAB53
MAXmalware (ai score=100)
MalwarebytesSpyware.RedLineStealer
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.Win32.MALREP.THCACBA
RisingSpyware.Stealer!8.3090 (CLOUD)
IkarusTrojan.Win32.Gencbl
FortinetPossibleThreat.MU
AVGWin32:Malware-gen
Qihoo-360Win32/TrojanSpy.RedLine.HxMB3AsB

How to remove Win32/GenCBL.ACH?

Win32/GenCBL.ACH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment