Malware

Win32/GenCBL.BPL removal tips

Malware Removal

The Win32/GenCBL.BPL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenCBL.BPL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the Vidar malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Win32/GenCBL.BPL?


File Info:

name: B75545242DDAEB269C35.mlw
path: /opt/CAPEv2/storage/binaries/ef508316ef3ce94b57a427ccc2114d4834a73baddcb33b7f54cc4a4bd3a18ab5
crc32: 3BAE61A3
md5: b75545242ddaeb269c35bd935a5ce638
sha1: b7f707ec23a126c7b2c7424889eccf4ac8617524
sha256: ef508316ef3ce94b57a427ccc2114d4834a73baddcb33b7f54cc4a4bd3a18ab5
sha512: 4814dff7957926809020c5b0dd081f23c5d4c9766250e39608cbfc9d81f1e692f1486817164ee4355fc21749aafaa5f54fea1a0d5df92b68c0f0004b9f6f295b
ssdeep: 49152:+Lt9KxGhkXmQVaupLIxHAmseeJ4KEi338DOwb6Ao3JgirEW:+Lt9KPXm63pLKHAn7WKhPk6NaAEW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132C5F1632F11DAE9D83A8971E46BD7F44A137E7AC56052C3E2C17F0A787280D903BE56
sha3_384: 112c1e50031d9a0bb4cd786c248c976f40b974b55e89f524736dedd8fa2098fc65dc9055c1f3b2f93ad9dd18f4334531
ep_bytes: eb02f1f650eb059ab8a89090e8180000
timestamp: 2022-02-01 05:44:15

Version Info:

FileDescription: iProDifX Installation Utility
FileVersion: 15.5.0.1
InternalName: iProDifX
LegalCopyright: Copyright (C) 2005, 2011
OriginalFilename: iProDifX.EXE
ProductName: iProDifX Application
ProductVersion: 15.5.0.0
Translation: 0x0409 0x04b0

Win32/GenCBL.BPL also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Chapak.4!c
MicroWorld-eScanTrojan.GenericKD.48217277
FireEyeTrojan.GenericKD.48217277
CAT-QuickHealTrojan.Chapak
McAfeeArtemis!B75545242DDA
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.92535
K7AntiVirusTrojan ( 0058ddd81 )
K7GWTrojan ( 0058ddd81 )
BitDefenderThetaGen:NN.ZexaF.34212.Es3@am@S3Ngi
CyrenW32/Obsidium.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenCBL.BPL
TrendMicro-HouseCallTROJ_FRS.0NA103B322
KasperskyTrojan.Win32.Chapak.fdfz
BitDefenderTrojan.GenericKD.48217277
AvastWin32:DangerousSig [Trj]
Ad-AwareTrojan.GenericKD.48217277
EmsisoftTrojan.GenericKD.48217277 (B)
ComodoMalware@#15e0fiunsg2vb
TrendMicroTROJ_FRS.0NA103B322
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-R + Troj/Agent-BIKW
IkarusTrojan.SuspectCRC
GDataTrojan.GenericKD.48217277
Antiy-AVLTrojan/Win32.Chapak
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftMalware.Win32.GenericMC.cc
ArcabitTrojan.Generic.D2DFBCBD
ZoneAlarmTrojan.Win32.Chapak.fdfz
MicrosoftExploit:Win32/ShellCode!ml
AhnLab-V3Downloader/Win.Agent.C4950239
VBA32BScope.Trojan.Wacatac
ALYacTrojan.GenericKD.48217277
MAXmalware (ai score=80)
MalwarebytesTrojan.MalPack.Obsidium
APEXMalicious
RisingTrojan.GenCBL!8.12138 (CLOUD)
YandexTrojan.GenCBL!e0H2jknfkyw
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.MU
AVGWin32:DangerousSig [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/GenCBL.BPL?

Win32/GenCBL.BPL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment