Crack

How to remove “HackTool:Win32/Wifidump”?

Malware Removal

The HackTool:Win32/Wifidump is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/Wifidump virus can do?

  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine HackTool:Win32/Wifidump?


File Info:

name: DC2D2F01F89D3A9321A8.mlw
path: /opt/CAPEv2/storage/binaries/f9f050463fdc12a0e1803763e6a51b21a97eb8cc2cf023f69a83dbccb296f448
crc32: 549F96A4
md5: dc2d2f01f89d3a9321a8f24d1113c182
sha1: 25cd748427e2dc4ef474786af01764fd94b35eff
sha256: f9f050463fdc12a0e1803763e6a51b21a97eb8cc2cf023f69a83dbccb296f448
sha512: 27c7a1262847d56ac3561cc538b6e09ea26785f415c609c2caae406ab4411f2f63b47dd1bef648478d800dcfbaf38b79e87725a4058c5ee693d365489a6b57ed
ssdeep: 12288:KdoQCvGzrEFyYMkW6Bq+E+ph6NWuOxhZ:KycIokBl3uNWdT
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A394E0502153DC25D19A0F71C532EAF4A03EAD54ED69E18B3AD8BF1B38B37C1A46290F
sha3_384: e11c55e35fa5bf521494a016733a69727301b2fbeb312def8da399e3e276054504afd121cbd8afe2caffb1113da93ee3
ep_bytes: 60be00d049008dbe0040f6ff57eb0b90
timestamp: 2014-02-04 10:53:48

Version Info:

CompanyName: SecurityXploded
FileDescription: Command-line based Wireless Password Recovery Tool
FileVersion: 2.0.0.0
InternalName: WiFiPasswordDump
LegalCopyright: Copyright (C) 2007-2014 SecurityXploded, All rights reserved
OriginalFilename: WiFiPasswordDump.exe
ProductName: WiFiPasswordDump
ProductVersion: 2.0.0.0
Translation: 0x0409 0x04b0

HackTool:Win32/Wifidump also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.SecurityXploded.1!c
Elasticmalicious (moderate confidence)
McAfeeRDN/Generic PUP.z
Cylanceunsafe
SangforHacktool.Win32.Agent.Vgwa
CrowdStrikewin/grayware_confidence_60% (D)
K7GWUnwanted-Program ( 004d38111 )
K7AntiVirusUnwanted-Program ( 004d38111 )
BitDefenderThetaGen:NN.ZexaF.36250.AmKfa0zs37ci
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSWTool.WiFiPasswordDump.A potentially unsafe
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:PSWTool.Win32.SecurityXploded.gen
NANO-AntivirusTrojan.Win32.Ool.iuiayb
McAfee-GW-EditionRDN/Generic PUP.z
SophosSecurity Xploded (PUA)
JiangminPSWTool.SecurityXploded.q
MicrosoftHackTool:Win32/Wifidump
ZoneAlarmnot-a-virus:HEUR:PSWTool.Win32.SecurityXploded.gen
GDataWin32.Riskware.Passdump.A
VBA32BScope.Trojan.Occamy
MalwarebytesRiskWare.SecurityXploded
TrendMicro-HouseCallTROJ_GEN.R002H06FE23
RisingHacktool.WiFiPasswordDump!8.1096 (CLOUD)
YandexTrojan.GenAsa!RzjDeZRKIdc
DeepInstinctMALICIOUS

How to remove HackTool:Win32/Wifidump?

HackTool:Win32/Wifidump removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment