Malware

What is “Win32/GenCBL.CTW”?

Malware Removal

The Win32/GenCBL.CTW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenCBL.CTW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/GenCBL.CTW?


File Info:

name: 3497796ACDC0640B5ECD.mlw
path: /opt/CAPEv2/storage/binaries/b766526ef3f585a2503d8eb666b828fb1a4aab6bd4521e983d4b387a2011bd0c
crc32: 33887EB1
md5: 3497796acdc0640b5ecdb5b0e209fd58
sha1: 25ea8c7cce31236eed7f7fe9cca9c91b5a066e5d
sha256: b766526ef3f585a2503d8eb666b828fb1a4aab6bd4521e983d4b387a2011bd0c
sha512: e79f377a27e62fc84161428895bfb49d4e289de142d0edf82f983b6e622343bca1357816ab19e8e385269c85d212871632bfddf5c11c2ab79233549428b7ef68
ssdeep: 98304:7ld3dGU2oYFKVxmZNY8uUbl+g3rNcB/atiYlvVDuIR:7lZYK/EZKWbl+sR5h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D567CF23E0BD2EFC24608B4F841E607D4250BE25E18F645DC6A7CBC9B52E6A25C975C
sha3_384: f98844bb1146a8d1e0159bf2c648299bc4f8c8cc1f26043701d34b446036b157fafd3b040a325ba64e4b2bcda4cfe8f4
ep_bytes: ff74240cff74240cff74240cb82e465f
timestamp: 2059-04-11 20:08:56

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName: chrome.exe
LegalCopyright: Copyright © 2023
LegalTrademarks:
OriginalFilename: chrome.exe
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Win32/GenCBL.CTW also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.66643447
FireEyeGeneric.mg.3497796acdc0640b
McAfeeArtemis!3497796ACDC0
K7AntiVirusTrojan ( 00598b491 )
K7GWTrojan ( 00598b491 )
CrowdStrikewin/malicious_confidence_70% (W)
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/GenCBL.CTW
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.xawtkw
BitDefenderTrojan.GenericKD.66643447
AvastWin32:Trojan-gen
SophosMal/Generic-S
VIPRETrojan.GenericKD.66643447
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.66643447 (B)
GDataTrojan.GenericKD.66643447
ArcabitTrojan.Generic.D3F8E5F7
ZoneAlarmTrojan.Win32.Agent.xawtkw
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32BScope.Trojan.MSIL.Agent
MAXmalware (ai score=82)
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0DDP23
RisingTrojan.Generic@AI.84 (RDML:oqu7mVXZ5CS/6A7uFIR09A)
MaxSecureTrojan.W32.MSIL.Agent.gen_265048
FortinetW32/GenCBL.CTW!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Win32/GenCBL.CTW?

Win32/GenCBL.CTW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment