Malware

Win32/GenCBL.DL removal guide

Malware Removal

The Win32/GenCBL.DL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenCBL.DL virus can do?

  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file

Related domains:

fEK.MYs
XCXhXCFYaDLHq.XCXhXCFYaDLHq

How to determine Win32/GenCBL.DL?


File Info:

crc32: A0DE8622
md5: c60aa6ca33dc49630ed8139d80d94d9d
name: upload_file
sha1: 33f678a5a83d4b3a22fb86a7cb81ae1dfdc8c8d5
sha256: fdec7bb225d252d1a257304a2e8dd58aa5ef1828f9ac653924c4e54bf71725a6
sha512: b9b755b72c747444cb766299413461c68f2af4c46dedc330b86f90edf6622de6b0983ff18cb81ad615ceed23ef8bbab1e678347b82c8763bc8c09c19e436c231
ssdeep: 24576:Kjyfe1E26yJ2NubMl9qedsRRhTTOz3BgP3BFa+wIw1+SsUgdhd:nfM6yJ6qPRhezM32+wIWAHd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Samepage Labs Inc. All rights reserved.
InternalName: Samepage.exe
FileVersion: 1.0.42624
CompanyName: Samepage Labs Inc.
SquirrelAwareVersion: 1
ProductName: Samepage
ProductVersion: 1.0.42624
FileDescription: Samepage
OriginalFilename: Samepage.exe
Translation: 0x0409 0x04b0

Win32/GenCBL.DL also known as:

MicroWorld-eScanTrojan.GenericKD.44107909
Qihoo-360Win32/Trojan.Spy.3e9
McAfeeArtemis!C60AA6CA33DC
CylanceUnsafe
AegisLabTrojan.Win32.Stealer.l!c
K7AntiVirusTrojan ( 005715cc1 )
BitDefenderTrojan.GenericKD.44107909
K7GWTrojan ( 005715cc1 )
ArcabitTrojan.Generic.D2A10885
InvinceaMal/Generic-S
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
AlibabaTrojanSpy:Win32/GenCBL.72f6e24e
Ad-AwareTrojan.GenericKD.44107909
EmsisoftTrojan.GenericKD.44107909 (B)
DrWebTrojan.MulDrop14.3315
ZillyaTrojan.Agent.Win32.851751
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.44107909
SophosMal/Generic-S
IkarusTrojan.Win32.Gencbl
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Wacatac.C!ml
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataTrojan.GenericKD.44107909
VBA32Trojan.Agent
ESET-NOD32a variant of Win32/GenCBL.DL
TrendMicro-HouseCallTROJ_GEN.R002H0DJI20
FortinetW32/Stealer.DL!tr
AVGFileRepMalware

How to remove Win32/GenCBL.DL?

Win32/GenCBL.DL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment