Crack

HackTool.PortScanner information

Malware Removal

The HackTool.PortScanner is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool.PortScanner virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Connects to an IRC server, possibly part of a botnet

Related domains:

irc.zief.pl
fget-career.com

How to determine HackTool.PortScanner?


File Info:

crc32: F950B9BF
md5: a34e7ca8724392fe1d7f0ac077ed02da
name: A34E7CA8724392FE1D7F0AC077ED02DA.mlw
sha1: 030c876fe6486c1d0fd6ba8717630ac44f8f31fe
sha256: f4dfd5e2c3123cb3c67f3f89ed0bd1d02fc7ad7318cedef7cac1fc108d08e215
sha512: 58e3068e6b87a622db00cc86e93a08bea2f7bf48ce0951f2e0b6225d696cda7c4a79e777019e09462c144dcabaec85148493161023c955e70fd14b7b944da8d5
ssdeep: 3072:Bg7bGkm5jNoy7DNuc9uif9qXTqDOZTd1amgBDHJrw:Bg/GkOoy/NeifsTj51qjr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2006 x738bx5b9dx5251
InternalName: ScanPort
FileVersion: 1.2 Build 2006.3.20
ProductName: ScanPortx7aefx53e3x626bx63cfx5de5x5177
ProductVersion: 1, 0, 0, 0
FileDescription: ScanPortx7aefx53e3x626bx63cfx5de5x5177 V1.2
OriginalFilename: ScanPort.exe
Translation: 0x0804 0x04b0

HackTool.PortScanner also known as:

BkavW32.RammitNNA.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Ramnit
CAT-QuickHealW32.Virut.Cur1
McAfeeW32/Ramnit.q
CylanceUnsafe
VIPREVirus.Win32.Ramnit.a (v)
AegisLabVirus.Win32.Nimnul.tn4U
SangforMalware
K7AntiVirusVirus ( 002fe95d1 )
BitDefenderWin32.Ramnit
K7GWVirus ( 002fe95d1 )
ArcabitWin32.Ramnit
InvinceaW32/Patched-I
BaiduWin32.Virus.Nimnul.a
CyrenW32/Ramnit.B!Generic
SymantecW32.Ramnit!inf
APEXMalicious
AvastWin32:RmnDrp [Inf]
ClamAVWin.Trojan.Ramnit-1847
KasperskyVirus.Win32.Nimnul.a
AlibabaVirus:Win32/Ramnit.gen2
NANO-AntivirusVirus.Win32.Ramnit.eslalb
ViRobotWin32.Ramnit.E
RisingVirus.Virut!1.A08B (CLASSIC)
Ad-AwareWin32.Ramnit
EmsisoftWin32.Ramnit (B)
ComodoVirus.Win32.Virut.CE@5jedjj
F-SecureMalware.W32/Ramnit.CD
DrWebWin32.Rmnet
ZillyaVirus.Nimnul.Win32.1
TrendMicroPE_RAMNIT.H
McAfee-GW-EditionBehavesLike.Win32.Ramnit.cc
MaxSecureVirus.Nimnul.A
FireEyeGeneric.mg.a34e7ca8724392fe
SophosW32/Patched-I
IkarusVirus.Win32.Virut
JiangminWin32/PatchFile.et
WebrootW32.Ramnit
AviraW32/Ramnit.CD
MAXmalware (ai score=100)
Antiy-AVLVirus/Win32.Nimnul.a
KingsoftWin32.Ramnit.la.30720
GridinsoftMalware.Win32.Pack.59456!se
MicrosoftVirus:Win32/Ramnit.A
ZoneAlarmVirus.Win32.Nimnul.a
GDataWin32.Virus.Ramnit.C
CynetMalicious (score: 100)
AhnLab-V3Win32/Ramnit.B
VBA32Virus.Win32.Nimnul.a
ALYacWin32.Ramnit
TACHYONVirus/W32.Ramnit.B
MalwarebytesHackTool.PortScanner
PandaW32/Cosmu.gen
ZonerTrojan.Win32.Ramnit.23698
ESET-NOD32Win32/Ramnit.A
TrendMicro-HouseCallPE_RAMNIT.H
TencentVirus.Win32.Nimnul.d
YandexTrojan.GenAsa!Qdr4RuYleEs
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Ramnit.A
BitDefenderThetaAI:FileInfector.EAEEA7850C
AVGWin32:RmnDrp [Inf]
Paloaltogeneric.ml
Qihoo-360Virus.Win32.Ramnit.B

How to remove HackTool.PortScanner?

HackTool.PortScanner removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment