Crack

About “HackTool:Win32/Patch” infection

Malware Removal

The HackTool:Win32/Patch is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/Patch virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine HackTool:Win32/Patch?


File Info:

crc32: 17D50C01
md5: 0d9b7abe952d6c1dc24750bf47969132
name: 0D9B7ABE952D6C1DC24750BF47969132.mlw
sha1: 982b2cb5d46d8409bb5f0d96efd93e7a9f8b80da
sha256: 9ec96e0facf95d1a08d4761aff436dac8318abd008c7284a4a22347069e8284d
sha512: 8cec775209e542a6ca3305ef90203f44fcc6a87a04d071e9e0600f19447f3f834b7d2921e0a33cec3ddc0970444e528da368c98b5f59bac85cde5e72f5c4fcba
ssdeep: 12288:HGsYlWDQfy1F8jr51lc+0vhOCF1dflSc46V1tKOGmixosyuC+muDXfvIFutmOyT:msYlWDo5c+6hVdfAcJVi6iwvIDXYhlI
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: PainteR
InternalName: Universal Adobe Patcher
FileVersion: 1.5.0.0
CompanyName: PainteR
ProductName: Universal Adobe Patcher
ProductVersion: 1.5.0.0
FileDescription: Universal Adobe Patcher
OriginalFilename: adobesnr.exe
Translation: 0x0409 0x04b0

HackTool:Win32/Patch also known as:

K7AntiVirusUnwanted-Program ( 004d38111 )
LionicRiskware.Win32.Patcher.1!c
Elasticmalicious (high confidence)
CAT-QuickHealTrojan.Agen
ALYacApplication.Agent.GWI
CylanceUnsafe
SangforHacktool.Win32.Patch.mt
CrowdStrikewin/malicious_confidence_100% (D)
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.e952d6
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/HackTool.Patcher.CH potentially unsafe
APEXMalicious
AvastFileRepMetagen [PUP]
ClamAVWin.Virus.Virut-6723776-0
BitDefenderApplication.Agent.GWI
ViRobotSpyware.Agent.631808
MicroWorld-eScanApplication.Agent.GWI
Ad-AwareApplication.Agent.GWI
SophosAdobe After Effects KeyGen (PUA)
ComodoApplicUnwnt@#1mc930v9lqf6y
BitDefenderThetaGen:NN.ZelphiF.34236.MmKfa4GlxamQ
VIPRETrojan.Win32.Generic!BT
TrendMicroHKTL_PATCHER
McAfee-GW-EditionRDN/Generic PUP.yn
FireEyeApplication.Agent.GWI
EmsisoftApplication.Keygen (A)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1AE2B24
MicrosoftHackTool:Win32/Patch
ArcabitApplication.Agent.GWI
SUPERAntiSpywareHack.Tool/Gen-Crack
GDataApplication.Agent.GWI
AhnLab-V3HackTool/Win32.Patcher.C2926504
McAfeeRDN/Generic PUP.yn
MAXmalware (ai score=91)
VBA32Trojan.Occamy
MalwarebytesRiskWare.Tool.HCK
TrendMicro-HouseCallHKTL_PATCHER
YandexTrojan.KillProc!MA+7Jtfux1w
IkarusHackTool.Patch.Adobe
FortinetRiskware/Patcher
AVGFileRepMetagen [PUP]
Paloaltogeneric.ml

How to remove HackTool:Win32/Patch?

HackTool:Win32/Patch removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment