Crack

How to remove “HackTool:Win32/ProcHack.SGA!MTB”?

Malware Removal

The HackTool:Win32/ProcHack.SGA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/ProcHack.SGA!MTB virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine HackTool:Win32/ProcHack.SGA!MTB?


File Info:

name: 44FE9061F9DE57D04692.mlw
path: /opt/CAPEv2/storage/binaries/29d46c1a1f84f8789811aa0b19a1066209aafe3795cb5de16ad7277f809e8389
crc32: 28DA8F4F
md5: 44fe9061f9de57d046929bd9082b9d2c
sha1: 90d82deb93e1803cfff58fd2f4d0ea4fe5d81210
sha256: 29d46c1a1f84f8789811aa0b19a1066209aafe3795cb5de16ad7277f809e8389
sha512: ba59bbaea54d8a1f02eaecc2cecc5e8883f9ee641d6f54f19e8f4c0fea996321a80cb55c12bd4e75ea8a2e305f0ad12ee3f5f7879d47c1edcce1dda68dbe05b1
ssdeep: 12288:ESbbRWutBQwaqdXiXi/cI0dG508RUi5tiE5IDAVRAdFmExWGmu4fZ/SMZoSsCY6:hTZaqdiXSp0c02uFG6dAk3xMnb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D5052323A21099CAF0660BB615F31718DCB4F3F295708977DF946CFA2D67A26CBA404D
sha3_384: 82f359ea80310078ce304f9504cd3bb09ece3ada9d694fb98fdfb1d70a5b3911fade7df9334c5c9889075454ac8f1ae2
ep_bytes: e80600000050e8bb010000558bec81c4
timestamp: 1972-12-25 05:33:23

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

HackTool:Win32/ProcHack.SGA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FlyStudio.4!c
tehtrisGeneric.Malware
MicroWorld-eScanApplication.Generic.3550663
ClamAVWin.Malware.Procpatcher-9875517-0
FireEyeGeneric.mg.44fe9061f9de57d0
SkyhighBehavesLike.Win32.RealProtect.cc
McAfeeArtemis!44FE9061F9DE
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005194cc1 )
K7GWTrojan ( 005194cc1 )
Cybereasonmalicious.b93e18
VirITTrojan.Win32.Click2.DFZZ
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderApplication.Generic.3550663
EmsisoftApplication.Generic (A)
BaiduWin32.Rootkit.Agent.f
VIPREApplication.Generic.3550663
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Backdoor.FlyAgent
GDataWin32.Riskware.FlyStudio.C
Webroot
GoogleDetected
Antiy-AVLTrojan/Win32.Wacatac.b
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.FlyStudio.~UJ@1sa9s6
ArcabitApplication.Generic.D362DC7
MicrosoftHackTool:Win32/ProcHack.SGA!MTB
VaristW32/S-759a1e41!Eldorado
ALYacApplication.Generic.3550663
MAXmalware (ai score=75)
MalwarebytesGeneric.Malware.AI.DDS
RisingRootkit.Agent!1.6784 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Flystudio.Y
FortinetW32/FlyStudio.C!tr
DeepInstinctMALICIOUS

How to remove HackTool:Win32/ProcHack.SGA!MTB?

HackTool:Win32/ProcHack.SGA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment