Malware

What is “MSIL/HipgnosisBrains.A potentially unwanted”?

Malware Removal

The MSIL/HipgnosisBrains.A potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/HipgnosisBrains.A potentially unwanted virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (11 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
hansotools.com
www.hansotools.com
ww7.hansotools.com
www.bing.com
fonts.googleapis.com
parking.parklogic.com
ocsp.pki.goog
fonts.gstatic.com

How to determine MSIL/HipgnosisBrains.A potentially unwanted?


File Info:

crc32: 810B7FB2
md5: ed4a3859f81eba5a7b0b764504fc0412
name: ED4A3859F81EBA5A7B0B764504FC0412.mlw
sha1: f99504bc8324bee3003fd992bc8bef97bf2d3433
sha256: eb34367275add603ef50db533de788aa867b39d2fc8a83f1221b1fc78ac39cd0
sha512: c53ee419f4274fc915b059fc700fd35100ba627108e6efc4b8886510f9734a57b7b26538e7060c859b25b1ccc2576b8b35ff7f1674714050d96c829f7f55f98a
ssdeep: 49152:lVCByalgrWQKHms5FRZfC+1ualFZnNVl3pldCbuOMy2dBwgYvQupL52:3CByalgrWQKHLFRU+1uCZblZlYbuOM2k
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xfffd HansoTools LLC
ProductName: Hanso CD Extractor
FileDescription: Hanso CD Extractor
FileVersion: 3.2.0.0
CompanyName: HansoTools LLC
Translation: 0x0409 0x0000

MSIL/HipgnosisBrains.A potentially unwanted also known as:

DrWebProgram.Unwanted.362
CylanceUnsafe
VIPRETrojan-Downloader.Win32.Agent
AegisLabTrojan.Win32.Generic.4!c
SymantecML.Attribute.HighConfidence
NANO-AntivirusTrojan.Win32.HipgnosisBrains.ezawql
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
SophosGeneric PUA PJ (PUA)
Ikarusnot-a-virus:Downloader.Agent
WebrootPUA.Gen
Antiy-AVLTrojan/Win32.Tgenic
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftPUA:Win32/Accelerator
GridinsoftTrojan.Win32.Downloader.oa
McAfeeArtemis!ED4A3859F81E
VBA32Downloader.Agent
MalwarebytesGeneric.Malware/Suspicious
ESET-NOD32a variant of MSIL/HipgnosisBrains.A potentially unwanted
RisingMalware.Undefined!8.C (CLOUD)
YandexPUA.Downloader!R6p5y4MQguc

How to remove MSIL/HipgnosisBrains.A potentially unwanted?

MSIL/HipgnosisBrains.A potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment