Malware

Win32:GenMalicious-HFP [Trj] removal tips

Malware Removal

The Win32:GenMalicious-HFP [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:GenMalicious-HFP [Trj] virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:GenMalicious-HFP [Trj]?


File Info:

name: CA3F0BC2FF7BD9EC3DD9.mlw
path: /opt/CAPEv2/storage/binaries/b4a28daca1fd0f2c29620a34f9025314ffaa31a68c2164a899f7f6572d108888
crc32: 244D6625
md5: ca3f0bc2ff7bd9ec3dd94e193443f0fd
sha1: 312bad7e1470c81cc1ccac79ac4d4afc7f65bfbf
sha256: b4a28daca1fd0f2c29620a34f9025314ffaa31a68c2164a899f7f6572d108888
sha512: df61da1771ceb098900134d74c06b6afa7220fb266b7d5659e9e864be6fd8ffe19464fe9309788ce1a12ef2cf3adf5e5241c6a8aa104dc58f54f7cabf9e169b6
ssdeep: 49152:tZoQCazSmuHzO0Ejxw596HoIo1I1kUey+dxJHdYyzuaQ+o:cwVp0ES596H7oGGURuDH6y/Q+o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D606C042F2817C72D11B1570542723BDEB395F821B38CA979390EEBA3C3396195B72E6
sha3_384: 79ce6ed081ef9706b3eeb34b108604d34d89048c2815d7ce42fbae2e3a91073c383fbe8be6f063124d4d15dabb673cff
ep_bytes: 00000000000000000000000000000000
timestamp: 2013-03-15 22:15:28

Version Info:

0: [No Data]

Win32:GenMalicious-HFP [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.ca3f0bc2ff7bd9ec
SkyhighBehavesLike.Win32.Generic.wh
McAfeeArtemis!CA3F0BC2FF7B
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
Cybereasonmalicious.e1470c
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Flystudio-9752414-0
AvastWin32:GenMalicious-HFP [Trj]
BaiduWin32.Trojan.FakeIME.d
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminHeur:Backdoor/Blackhole
VaristW32/VBInject.L.gen!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.1OV7PVV
GoogleDetected
VBA32Tool.CrosFire
Cylanceunsafe
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:GenMalicious-HFP [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32:GenMalicious-HFP [Trj]?

Win32:GenMalicious-HFP [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment