Malware

Win32/GenCBL.CHD removal guide

Malware Removal

The Win32/GenCBL.CHD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenCBL.CHD virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper

How to determine Win32/GenCBL.CHD?


File Info:

name: C348DE43B0F16779C94E.mlw
path: /opt/CAPEv2/storage/binaries/aa529f72d2015b72654fbe5e04d6d868c29c9648d6d093890ab9acc24d46deab
crc32: 15A2F98D
md5: c348de43b0f16779c94ed0d15185e675
sha1: 581cbff39f3612ae1e59356df5beff5e8d29d4af
sha256: aa529f72d2015b72654fbe5e04d6d868c29c9648d6d093890ab9acc24d46deab
sha512: 37b11a985df702472e980332c7071e3d747cd3c26f8c4c8baee2f6e5fdffe1d049ee97d422f19ff17590d653000d4a6e4aacdec20720a85abbd2f61198b3dfb2
ssdeep: 6144:ZYa62hBnjVgbjY9JLR2lYnZVqEN700rLf/ONbi1:ZYUjnv995N7z+b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175A4E0103BD2D81BC2D34B394BAAD729E7B8EE006E6B52073351774EFE367859D46281
sha3_384: c7db02fc094da26cfd187c06fd67f3e4204d721c17ad56d86df3403dd3049e474f483626556bdd2eaa06141f40bc0c85
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:56:47

Version Info:

Comments: Rearimpuissant
CompanyName: FAGINSPEKTRS
FileDescription: Fiercely35
FileVersion: 14.20.13
LegalCopyright: pupilloscopere
LegalTrademarks: Forvrels
ProductName: Inturnedcoor241
Translation: 0x0409 0x04b0

Win32/GenCBL.CHD also known as:

MicroWorld-eScanTrojan.GenericKD.39838884
FireEyeTrojan.GenericKD.39838884
ALYacTrojan.GenericKD.39838884
CylanceUnsafe
ZillyaTrojan.GenCBL.Win32.7676
K7AntiVirusTrojan ( 00594a251 )
AlibabaTrojan:Win32/Shelsy.1fed3b3f
K7GWTrojan ( 00594a251 )
CyrenW32/NSIS_Injector.A.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenCBL.CHD
TrendMicro-HouseCallTROJ_GEN.R002C0PFP22
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Shelsy.gen
BitDefenderTrojan.GenericKD.39838884
AvastWin32:Malware-gen
TencentWin32.Trojan.Falsesign.Swaq
Ad-AwareTrojan.GenericKD.39838884
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Nekark.hlwwz
VIPRETrojan.GenericKD.39838884
TrendMicroTROJ_GEN.R002C0PFP22
McAfee-GW-EditionRDN/Generic.dx
EmsisoftTrojan.GenericKD.39838884 (B)
IkarusTrojan.Inject
GDataTrojan.GenericKD.39838884
AviraTR/AD.Nekark.hlwwz
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Generic.D25FE4A4
ZoneAlarmHEUR:Trojan.Win32.Shelsy.gen
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 99)
McAfeeRDN/Generic.dx
MAXmalware (ai score=81)
FortinetNSIS/Injector.AOW!tr
AVGWin32:Malware-gen
PandaTrj/Chgt.AA
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/GenCBL.CHD?

Win32/GenCBL.CHD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment