Ransom

Ransom:Win32/Haknata removal

Malware Removal

The Ransom:Win32/Haknata is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Haknata virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Clears Windows events or logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom:Win32/Haknata?


File Info:

crc32: 9D6C28B3
md5: 941351e532a83efa8c7ee26c6ba98f33
name: 941351E532A83EFA8C7EE26C6BA98F33.mlw
sha1: 595e51015819abffd023ad918305cb45c2e07329
sha256: 538b745b813d53bdb624fa66ee304525f15dee010609bf8b2d2cfec4f0a0cfdf
sha512: 3f0618a6c7875554ff9e947b1948decc0d3f3a490f8fe5715e1aaaf9ac3ccc2768195e30eb56aae61cd27c092450e8989f79e5c46677baef79a2ab722672609e
ssdeep: 24576:mPlI0vZYBxyG942+6ytOnvekeTIgG2qqRn0fLnjYY1L:/yOveTIsqqR0fL8Y
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ransom:Win32/Haknata also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 7000000f1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10157
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Xpan
CylanceUnsafe
ZillyaTrojan.Deshacop.Win32.755
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.15819a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.XRatLocker.D
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Razy-7547555-0
KasperskyTrojan-Ransom.Win32.Xpan.c
NANO-AntivirusTrojan.Win32.Deshacop.ejnnls
TencentWin32.Trojan.Raas.Auto
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34678.JvW@aeJ01te
McAfee-GW-EditionBehavesLike.Win32.Sytro.th
FireEyeGeneric.mg.941351e532a83efa
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Deshacop.tf
AviraTR/Crypt.XPACK.Gen
MicrosoftRansom:Win32/Haknata
AhnLab-V3Trojan/Win32.Xpan.R249365
Acronissuspicious
McAfeeArtemis!941351E532A8
MAXmalware (ai score=98)
VBA32TrojanRansom.Xpan
MalwarebytesMalware.Heuristic.1003
PandaTrj/GdSda.A
RisingRansom.Haknata!8.E480 (CLOUD)
IkarusTrojan-Ransom.FileCrypter
FortinetW32/XRatLocker.D!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HgIASRoA

How to remove Ransom:Win32/Haknata?

Ransom:Win32/Haknata removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment