Malware

What is “PWS:Win32/Hooker”?

Malware Removal

The PWS:Win32/Hooker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Hooker virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Sniffs keystrokes
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine PWS:Win32/Hooker?


File Info:

crc32: C8AECF87
md5: 73379b9249cef38736f57b25b2e03552
name: 73379B9249CEF38736F57B25B2E03552.mlw
sha1: c21423f68e7aa064f8b9d1603cf0a5951a78f3a6
sha256: 9f2f06fb17540646b145774627487158bfe3ad9a35077979d5a761330b49d1ac
sha512: 80a283c09e946bdd08d1b1bd8bc6218efb4cd358c48a2aab636ffcf5d9b5164b6d6a049c58a908d6a777808a3a0224d7a1bf1943a94d0abd3d2ea98f16220e74
ssdeep: 384:KDvD7v4ytjTayvs7NeL7QripMx0gHjxajWIvE+9MWEvO0Ka6aeg8utcUsJK8:K7D7v4yZGyvs7NeL6EMlHjkjlXMWKTKH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/Hooker also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Hooker.30
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.Hooker.Win32.4
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanPSW:Win32/Hooker.e134aa52
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.249cef
CyrenW32/Risk.CPPG-4043
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.Hooker.A
APEXMalicious
AvastWin32:KeyHooker [Trj]
ClamAVWin.Trojan.Hooker-1
KasperskyTrojan-PSW.Win32.Hooker.based
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Hooker.fgwv
ViRobotTrojan.Win32.Keylogger.F
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentMalware.Win32.Gencirc.116d8fb1
Ad-AwareTrojan.Ransom.Cerber.1
SophosTroj/Hooker-A
ComodoTrojWare.Win32.PSW.Hooker.A@46w3
BitDefenderThetaAI:Packer.9A9A93DD1A
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_PSHOOKER.A
McAfee-GW-EditionPWS-Hooker
FireEyeGeneric.mg.73379b9249cef387
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/PSW.Hooker.a
WebrootW32.Gen.Bt
AviraTR/PSW.Hooker.A2
MicrosoftPWS:Win32/Hooker
ArcabitTrojan.Ransom.Cerber.1
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Win-Trojan/Hooker.21504_v24
McAfeePWS-Hooker
MAXmalware (ai score=99)
VBA32BScope.TrojanPSW.Hooker
MalwarebytesMalware.AI.2194920081
PandaTrj/PSW.Hooker.A
TrendMicro-HouseCallTROJ_PSHOOKER.A
RisingTrojan.PSW.Hooker.ec (CLOUD)
IkarusTrojan-PWS.Win32.Hooker
FortinetW32/PWS.HOOK.A!tr
AVGWin32:KeyHooker [Trj]
Paloaltogeneric.ml

How to remove PWS:Win32/Hooker?

PWS:Win32/Hooker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment