Trojan

Trojan.RegistryDisabler.HGqaa8fkE1em removal instruction

Malware Removal

The Trojan.RegistryDisabler.HGqaa8fkE1em is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RegistryDisabler.HGqaa8fkE1em virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A potential decoy document was displayed to the user
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Interacts with known DarkComet registry keys
  • Attempts to disable UAC
  • Harvests information related to installed mail clients
  • Attempts to modify or disable Security Center warnings
  • Creates known Fynloski/DarkComet mutexes
  • Anomalous binary characteristics

Related domains:

nickenhack.ddns.net

How to determine Trojan.RegistryDisabler.HGqaa8fkE1em?


File Info:

crc32: 51E9F1EB
md5: bbfd54a13f25f61762e6b82e91d8a104
name: f90b5327b96ac4ca.exe
sha1: 85d75b808dd1cff7b94323449557acd67572b01a
sha256: cc09241a01c4d3a4240f0882fb89056489de196590986c05b16a9bc1c69fbd95
sha512: 986bb4fbf1a138d9b8b21e0a73bf626fc4d3b44462921986a54318c578c21e80d51c2ce5e7016b0198a3f9fb192010b0bea78a0146f935d00377e99f99c58895
ssdeep: 12288:0nBQ7/CClTmgSyC5xwP671T64bxvQLvskTGUd:gW7/CmTYYP671WsZQzNiM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.RegistryDisabler.HGqaa8fkE1em also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Trojan.RegistryDisabler.HGqaa8fkE1em
FireEyeGeneric.mg.bbfd54a13f25f617
McAfeeGenericRXDR-OQ!BBFD54A13F25
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Rbot.leZz
SangforMalware
K7AntiVirusTrojan ( 004bdc281 )
BitDefenderGen:Trojan.RegistryDisabler.HGqaa8fkE1em
K7GWTrojan ( 004bdc281 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_BINDER.SMBD
BaiduWin32.Trojan-Dropper.Delf.as
F-ProtW32/Trojan2.PZJI
SymantecSMG.Heur!gen
TotalDefenseWin32/Fynloski.ZHLKEDD
APEXMalicious
AvastWin32:GenMalicious-ICH [Trj]
ClamAVWin.Trojan.Injector-6297685-1
GDataGen:Trojan.RegistryDisabler.HGqaa8fkE1em
KasperskyTrojan-Dropper.Win32.Delf.eimp
AlibabaTrojanDropper:Win32/Dorv.ca10ba7c
NANO-AntivirusTrojan.Win32.Delf.flagce
ViRobotTrojan.Win32.A.Scar.451584.A
TencentMalware.Win32.Gencirc.10b0cf09
Endgamemalicious (high confidence)
EmsisoftGen:Trojan.RegistryDisabler.HGqaa8fkE1em (B)
ComodoTrojWare.Win32.TrojanDropper.Delf.SOC@572vwy
F-SecureBackdoor.BDS/Backdoor.Gen
DrWebTrojan.Packed.20771
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.hc
MaxSecureDropper.Delf.EFNZ
Trapminemalicious.high.ml.score
SophosMal/Behav-001
IkarusWorm.Win32.Agent
CyrenW32/Trojan.VVWT-8174
JiangminTrojan/Genome.bawa
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.DarkKomet
MicrosoftTrojan:Win32/Dorv.A
ArcabitTrojan.RegistryDisabler.HGqaa8fkE1em
ZoneAlarmTrojan-Dropper.Win32.Delf.eimp
AhnLab-V3Trojan/Win32.Ruftar.R30190
Acronissuspicious
BitDefenderThetaAI:Packer.D172892021
ALYacGen:Trojan.RegistryDisabler.HGqaa8fkE1em
VBA32TrojanDropper.Delf
MalwarebytesTrojan.Agent.DF
PandaTrj/Genetic.gen
ESET-NOD32Win32/TrojanDropper.Delf.OEF
TrendMicro-HouseCallTROJ_BINDER.SMBD
RisingBackdoor.Darkcomet!8.1117F (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/DROPPER.PAG!tr
Ad-AwareGen:Trojan.RegistryDisabler.HGqaa8fkE1em
AVGWin32:GenMalicious-ICH [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dropper.252

How to remove Trojan.RegistryDisabler.HGqaa8fkE1em?

Trojan.RegistryDisabler.HGqaa8fkE1em removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment