Crack

HackTool:Win32/Defendercontrol removal instruction

Malware Removal

The HackTool:Win32/Defendercontrol is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/Defendercontrol virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine HackTool:Win32/Defendercontrol?


File Info:

name: 46138D264AB20DF0D0D9.mlw
path: /opt/CAPEv2/storage/binaries/d8fab196936a0daa26227517ecaed5ee4cfc6cb4b95b258f810bf55a98b1856a
crc32: 2116FA7F
md5: 46138d264ab20df0d0d92f3046fad199
sha1: 4b53652574ce6ded87c9884bc88b491424e83e79
sha256: d8fab196936a0daa26227517ecaed5ee4cfc6cb4b95b258f810bf55a98b1856a
sha512: d55d34bcab07653c165fa561f552e1ede297c45b9d0ec9fd8a71f507934605296ec0a64761e0eba868e8ded74a9f3ae745c11b1a050bac85b78ecb9315101211
ssdeep: 49152:ngwRCifu1DBgutBPNQeTyemHD1BwBBm0eZOP/+EbPlVw6lTcJRKbfAPD0qBt:ngwRCvguPP21emsBYQ+EJGgc4Y4q7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AD52315EBC2C773D062E27BE58C6650C96EAF0C0B2487F30A943AF919B8583477DE59
sha3_384: d5164c19fb32dd9d892748617b9c408db18fa5a6175bf5bc304dca9947a1d47801726fffe81e1a9e01b0d557f792f815
ep_bytes: 558bec6aff6870c4410068c095410064
timestamp: 2012-12-31 00:38:51

Version Info:

0: [No Data]

HackTool:Win32/Defendercontrol also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Mimic.4!c
DrWebTrojan.Encoder.37211
MicroWorld-eScanTrojan.Generic.32519181
FireEyeTrojan.Generic.32519181
McAfeeArtemis!46138D264AB2
MalwarebytesGeneric.Ransom.FileCryptor.DDS
SangforTrojan.Win32.Mimic.V9oh
AlibabaRansom:Win32/Mimic.2b8690bc
Cybereasonmalicious.574ce6
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Filecoder.Mimic.A
APEXMalicious
KasperskyTrojan-Ransom.Win32.Mimic.o
BitDefenderTrojan.Generic.32519181
AvastWin32:Evo-gen [Trj]
SophosMal/Generic-S
VIPRETrojan.Generic.32519181
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
EmsisoftTrojan.Generic.32519181 (B)
GDataTrojan.Generic.32519181
ArcabitTrojan.Generic.D1F0340D
ZoneAlarmTrojan-Ransom.Win32.Mimic.o
MicrosoftHackTool:Win32/Defendercontrol
AhnLab-V3Malware/Win.Malware-gen.C5333461
ALYacTrojan.Generic.32519181
MAXmalware (ai score=85)
Cylanceunsafe
TencentMalware.Win32.Gencirc.10bdfc65
YandexTrojan.Agent!L5Kdg5Nx8Co
FortinetPossibleThreat.ARN.M
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove HackTool:Win32/Defendercontrol?

HackTool:Win32/Defendercontrol removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment