Crack

HackTool:Win32/WMIShell.A removal guide

Malware Removal

The HackTool:Win32/WMIShell.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/WMIShell.A virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Checks the version of Bios, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine HackTool:Win32/WMIShell.A?


File Info:

crc32: 8D3975FE
md5: 321136935f0d8a81e2a907c754416da8
name: 321136935F0D8A81E2A907C754416DA8.mlw
sha1: 1c1349993fad2e7840b9793294037acdb03cb40a
sha256: f95754aa132187877cff090d14af07900adfa10c76a278c8b377f37bd6a992c9
sha512: e673f4082e01261d4c52b7270ac39956f2d7efba8c0a79f7efc00e61a4fd250cdf9539f1f20f998e82820302c629c08fba5001803526c3dee379a69144bc8558
ssdeep: 6144:0O/2r3CO56cmjmiIqENMC0DcWgU28EE6QCIOeBiN0ey8KVCFZxx4:07d6cimicMcZfuLM0ey8KVC4
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

HackTool:Win32/WMIShell.A also known as:

BkavW32.AIDetectVM.malware1
DrWebTool.Siggen.6945
MicroWorld-eScanTrojan.GenericKD.36285787
FireEyeGeneric.mg.321136935f0d8a81
ALYacMisc.HackTool.Exploiter
MalwarebytesAutoKMS.HackTool.Patcher.DDS
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusAdware ( 005693e61 )
BitDefenderTrojan.GenericKD.36285787
K7GWAdware ( 005693e61 )
Cybereasonmalicious.93fad2
BitDefenderThetaGen:NN.ZexaF.34804.BCW@ayDBsW
CyrenW32/Trojan.FFLT-0472
SymantecHacktool
APEXMalicious
AvastWin32:Malware-gen
KasperskyExploit.Win32.WMI.c
AlibabaExploit:Win32/WMIShell.41c62f95
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
ViRobotHackTool.Exploit.446464
TencentWin32.Exploit.Wmi.Lfzl
Ad-AwareTrojan.GenericKD.36285787
SophosMal/Generic-S
ComodoTrojWare.Win32.Amtar.KNB@4wlm66
F-SecureHeuristic.HEUR/AGEN.1103502
McAfee-GW-EditionBehavesLike.Win32.Lovgate.gc
EmsisoftTrojan.GenericKD.36285787 (B)
SentinelOneStatic AI – Suspicious PE
JiangminExploit.WMI.g
AviraHEUR/AGEN.1103502
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftHackTool:Win32/WMIShell.A
ArcabitTrojan.Generic.D229AD5B
ZoneAlarmExploit.Win32.WMI.c
GDataTrojan.GenericKD.36285787
CynetMalicious (score: 100)
AhnLab-V3HackTool/Win32.Exploit.C1494079
Acronissuspicious
McAfeeArtemis!321136935F0D
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Toksteal.C
TrendMicro-HouseCallTROJ_GEN.R002H0CB221
RisingTrojan.Toksteal!8.137D (TFE:4:ZJlLZe3XNkF)
YandexExploit.WMI!i6gzahEMS0I
IkarusTrojan.Win32.Toksteal
FortinetW32/SfEngine.A!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Win32/Trojan.498

How to remove HackTool:Win32/WMIShell.A?

HackTool:Win32/WMIShell.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment