Malware

Win32/GenCBL.ANH malicious file

Malware Removal

The Win32/GenCBL.ANH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenCBL.ANH virus can do?

  • Presents an Authenticode digital signature
  • Anomalous binary characteristics

How to determine Win32/GenCBL.ANH?


File Info:

crc32: 643824DC
md5: 39434fddf0bd137bac7b80d41f4ea12f
name: 39434FDDF0BD137BAC7B80D41F4EA12F.mlw
sha1: 80a096706a24904eef6a947d90dbf197d259164e
sha256: 20906f345b3c3cefe54adc059792cfa4c098f0547df80c8c7e70ff79c914ae38
sha512: e0a7479885247bd87cffd263969d10f48ab5e57ec27d72be67094adc6a6af6b83ad68d1fe0858fb642adb5a00535596e710f5d605720990bd800be84d81b215a
ssdeep: 49152:ser8RDbm54GWHoZwkO9grlb2kT3+5qoKjWDA6tObkmdHiSi/U7UWLTib9D75gBXP:Mn+pSCyYKdGn
type: PE32+ executable (GUI) x86-64, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
Assembly Version: 0.0.0.0
InternalName: RuntimeBroker.exe
FileVersion: 6.3.9600.17415 (winblue_r4
CompanyName: Microsoftxae Windowsxae Operating System
LegalTrademarks: Runtime Broker
Comments: Runtime Broker
ProductName: Microsoft Corporation
ProductVersion: 6.3.9600.17415 (winblue_r4
FileDescription: Runtime Broker
OriginalFilename: RuntimeBroker.exe

Win32/GenCBL.ANH also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.17130
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
Cybereasonmalicious.06a249
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/GenCBL.ANH
AvastWin64:DangerousSig [Trj]
KasperskyTrojan.Win32.Witch.djy
BitDefenderTrojan.GenericKD.37192578
MicroWorld-eScanTrojan.GenericKD.37192578
Ad-AwareTrojan.GenericKD.37192578
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.39434fddf0bd137b
EmsisoftMalCert.A (A)
MicrosoftTrojan:MSIL/AgentTesla.STA
ArcabitTrojan.Generic.D2378382
GDataTrojan.GenericKD.37192578
McAfeeArtemis!39434FDDF0BD
MAXmalware (ai score=81)
PandaTrj/CI.A
AVGWin64:DangerousSig [Trj]
Qihoo-360Win64/Trojan.Generic.HgEASX0A

How to remove Win32/GenCBL.ANH?

Win32/GenCBL.ANH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment