Crack

HackTool:Win32/Gendows removal tips

Malware Removal

The HackTool:Win32/Gendows is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/Gendows virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine HackTool:Win32/Gendows?


File Info:

crc32: 4704A38F
md5: 17db8ab7c489bc333f3340e6138df9ce
name: windows-loader.exe
sha1: 59c759fbcbb000747cdc3635a8078ecdfd1fd5ac
sha256: 0c2c2658b319a09659a011895fb4528eec8a5b8ff3a5a4c64f0873145fbd044f
sha512: 9ff558c1cdd2f125e53588e058888f799383e1969611f665c8d2ae5d1f67b7c8f90d711df07bebc4614584bf609b70b74e16d40881886c971c26ac6894227903
ssdeep: 49152:rddKCu/A91hIMXTYxtI0M8Lcpr4P9jxKA:hdluK5T+pNbFwA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: windows loader
FileVersion:
CompanyName: windows loader
LegalTrademarks: windows loader
Comments: windows loader
ProductName: windows loader
FileDescription: 3.1
Translation: 0x0804 0x03a8

HackTool:Win32/Gendows also known as:

MicroWorld-eScanApplication.Hacktool.UK
FireEyeApplication.Hacktool.UK
CAT-QuickHealHacktool.Gendows
McAfeeArtemis!17DB8AB7C489
CylanceUnsafe
K7AntiVirusUnwanted-Program ( 004bc1f91 )
BitDefenderApplication.Hacktool.UK
K7GWUnwanted-Program ( 004bc1f91 )
F-ProtW32/A-aa93a15d!Eldorado
SymantecSMG.Heur!gen
TotalDefenseWin32/Tnega.XAWX!suspicious
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Aa93a15d-6745814-0
GDataWin32.Riskware.WinActivator.A
KasperskyHackTool.Win32.KMSAuto.et
AlibabaHackTool:Win32/KMSAuto.5a80fc50
SophosWindows 7 Loader (PUA)
ComodoApplicUnwnt@#1fa2x5ge44vwo
ZillyaTool.WinActivator.Win32.39
TrendMicroCRCK_ACTIVATOR
McAfee-GW-EditionArtemis!PUP
MaxSecureTrojan.Malware.2588.susgen
EmsisoftApplication.Hacktool.UK (B)
CyrenW32/A-aa93a15d!Eldorado
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.StartPage.gen
MicrosoftHackTool:Win32/Gendows
ArcabitApplication.Hacktool.UK
ZoneAlarmHackTool.Win32.KMSAuto.et
BitDefenderThetaGen:NN.ZexaF.32248.WpNfaCUzYHli
MalwarebytesHackTool.WinActivator
ZonerPUA.Win32.64619
ESET-NOD32Win32/HackTool.WinActivator.I potentially unsafe
TrendMicro-HouseCallCRCK_ACTIVATOR
YandexHackTool.WinActivator!
Ikaruspossible-Threat.Hacktool.Windows
eGambitUnsafe.AI_Score_99%
AVGFileRepMetagen [Malware]
Cybereasonmalicious.7c489b
Qihoo-360Trojan.Generic

How to remove HackTool:Win32/Gendows?

HackTool:Win32/Gendows removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment