Crack

HackTool:Win32/LSADump!dha removal tips

Malware Removal

The HackTool:Win32/LSADump!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/LSADump!dha virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the mimikatz malware family
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine HackTool:Win32/LSADump!dha?


File Info:

name: 63FA6FCBFA2917632F68.mlw
path: /opt/CAPEv2/storage/binaries/8fd8bcf4cf822083e88fd38f0d846e850e73b335f76754a3caf9f46b958a1be6
crc32: 3514EF1D
md5: 63fa6fcbfa2917632f68d2cc898e5e3f
sha1: e0198014b50a003b3a3b1b8cbaa4c5ad013f3c5d
sha256: 8fd8bcf4cf822083e88fd38f0d846e850e73b335f76754a3caf9f46b958a1be6
sha512: a406f57c8021e8b13fc31f79233caec4bd9eb1569d7d13a27d4d0f5521e584c530b7ad0fcd1e2371064e717fafd6afd19bd849b23f3bba47a45272ef089d6d57
ssdeep: 24576:/7B6YLhXEk7zjN5pbNHGToa6EBwoENGnfIxIK3I+kYvaPUEL:/1rfp4oWByNGnfw13INPhL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D7250222B261C0B9F5AA057395F24734AEB44FD0A4B4CE8BD780FF719D72A20566F709
sha3_384: 5170f781736f228a874b20a58da395e8afd89acef6e0340aeaf9418a815492a9956d25a0d2cb92384fcb41cc4a0ddf04
ep_bytes: 558bec6aff68505f42006818c5410064
timestamp: 2023-06-23 09:53:06

Version Info:

0: [No Data]

HackTool:Win32/LSADump!dha also known as:

BkavW32.AIDetectMalware
DrWebTrojan.DownLoader12.61141
MicroWorld-eScanGen:Variant.Jaik.103475
FireEyeGeneric.mg.63fa6fcbfa291763
ALYacGen:Variant.Jaik.103475
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Babar.210753
SangforTrojan.Win32.Save.BlackMoon
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36318.@qZ@ayciaMpb
CyrenW64/S-b61adc75!Eldorado
SymantecInfostealer!im
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.OJO
APEXMalicious
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyHEUR:Backdoor.Win32.Zegost.gen
BitDefenderGen:Variant.Jaik.103475
NANO-AntivirusTrojan.Win32.MqW.jxexzq
AvastWin32:BackdoorX-gen [Trj]
EmsisoftApplication.Generic (A)
F-SecureHeuristic.HEUR/AGEN.1356881
TrendMicroTROJ_GEN.R03BC0WGD23
McAfee-GW-EditionBehavesLike.Win32.VirRansom.fc
Trapminemalicious.high.ml.score
SophosBlackMoon Packed (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1DPEYYJ
GoogleDetected
AviraHEUR/AGEN.1356881
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Blamon.a
ArcabitTrojan.Jaik.D19433
ZoneAlarmBackdoor.Win32.Zegost.mtuwr
MicrosoftHackTool:Win32/LSADump!dha
CynetMalicious (score: 100)
McAfeeArtemis!63FA6FCBFA29
VBA32BScope.Trojan.MulDrop
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0WGD23
IkarusTrojan.Crypt
FortinetW32/CoinMiner.WP!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.bfa291
DeepInstinctMALICIOUS

How to remove HackTool:Win32/LSADump!dha?

HackTool:Win32/LSADump!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment