Malware

Win32/GenCBL.ANJ information

Malware Removal

The Win32/GenCBL.ANJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenCBL.ANJ virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Malay (Brunei Darussalam)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/GenCBL.ANJ?


File Info:

crc32: 23F392C2
md5: 88e85b7a234ccb1fd2d1dd6394a90ac6
name: 88E85B7A234CCB1FD2D1DD6394A90AC6.mlw
sha1: 6b489b90a4975436c2ecdfc0d9f203412290d8b1
sha256: aef50fda005e037a443df81e3dbaa530c7f4d661bacb90f40f955647c1ab33fd
sha512: 5f5936cede4e0e1af685ec12a82fff63ae01b29a5f08cde4e99f83c3e75ae53985841fde05ea6d2f7ce7871973e9a761de80835f1fe75dcaf3fe0a2f52e1d282
ssdeep: 49152:iO9kbQbTM2tjJy6kPEmMru1TCstdTzKkgygdYZBDBUMdBSm:iO92sfjU6krM2EHeSm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014
Assembly Version: 2.1.9.0
InternalName: SidNameU.exe
FileVersion: 2.1.9.1
CompanyName:
LegalTrademarks:
Comments:
ProductName: InvoicesManager_ver2
ProductVersion: 2.1.9.1
FileDescription: InvoicesManager_ver2
OriginalFilename: SidNameU.exe

Win32/GenCBL.ANJ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0057ef641 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.19871
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37194590
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:MSIL/Reline.ed31206a
K7GWTrojan ( 0057ef641 )
Cybereasonmalicious.0a4975
CyrenW32/Trojan.QNOA-6031
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenCBL.ANJ
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-PSW.MSIL.Reline.dhg
BitDefenderTrojan.GenericKD.37194590
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.GenericKD.37194590
TencentMsil.Trojan-qqpass.Qqrob.Edxw
Ad-AwareTrojan.GenericKD.37194590
SophosMal/Generic-S
ComodoMalware@#2l26kxfixvhe8
BitDefenderThetaGen:NN.ZexaF.34790.9I1@am4XtQcO
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.88e85b7a234ccb1f
EmsisoftTrojan.GenericKD.37194590 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Redcap.etmaz
eGambitUnsafe.AI_Score_67%
KingsoftWin32.PSWTroj.Reline.d.(kcloud)
MicrosoftTrojan:Win32/Tnega!ml
GridinsoftTrojan.Heur!.010100A1
GDataMSIL.Trojan-Stealer.NetSteal.4GZ7HD
AhnLab-V3Trojan/Win.Generic.R429793
McAfeeArtemis!88E85B7A234C
MAXmalware (ai score=84)
VBA32BScope.Trojan.Fuerboos
MalwarebytesSpyware.PasswordStealer
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CG621
YandexTrojan.PWS.Reline!AGsJjVkp32M
IkarusTrojan.Win32.Generic
FortinetW32/Reline.ANJ!tr.pws
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanPSW.Generic.HxMBZ7sA

How to remove Win32/GenCBL.ANJ?

Win32/GenCBL.ANJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment