Crack

VHO:HackTool.Win32.NetScanner removal guide

Malware Removal

The VHO:HackTool.Win32.NetScanner is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VHO:HackTool.Win32.NetScanner virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine VHO:HackTool.Win32.NetScanner?


File Info:

name: CC4A594CBE233A60CE64.mlw
path: /opt/CAPEv2/storage/binaries/b6eb1e2a36bc2cd6c0c7ec22af1250f07709f205b70cc258a13e67cc7c1a9776
crc32: A21105CD
md5: cc4a594cbe233a60ce64fe79be9e3d91
sha1: 345557b4a27347fce4e4e11bcbda0b2d0ac90957
sha256: b6eb1e2a36bc2cd6c0c7ec22af1250f07709f205b70cc258a13e67cc7c1a9776
sha512: 0540f5cd30b555881a2f17664ea91c275d53c47373468d857f08b709a007bbb8f803415508ddb02da9940935504bfc1525dfe9e75ce87fcf80dc33a5b96eec20
ssdeep: 24576:h0jnQSWio3208Nsnd7PEZh5G1mZVBYPVI+1/+pk6Rr+b5YCVQIY6fzVTA1uFJFGB:hZVQGzViuxA+yN08Mdyay4Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DDC56B23E54285B2E108167069F68B3A9E34EE710E315AD797E0FEB93F313709A6711D
sha3_384: e4b9d738245e14d84d2b27aef4fc6d4077a0eccb1bf20c5f875dae6f823cba081f87b5459c6c0e11691f7c80a8d0558e
ep_bytes: 558bec6aff689885650068fc3b550064
timestamp: 2021-11-04 10:12:11

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

VHO:HackTool.Win32.NetScanner also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
FireEyeGeneric.mg.cc4a594cbe233a60
SkyhighBehavesLike.Win32.Generic.vh
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaE.36802.Js0@aKhIZ7mH
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Trojanx-9951053-0
KasperskyVHO:HackTool.Win32.NetScanner.gen
EmsisoftApplication.Generic (A)
GoogleDetected
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
VaristW32/Trojan.GRW.gen!Eldorado
Antiy-AVLRiskWare/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
ZoneAlarmVHO:HackTool.Win32.NetScanner.gen
GDataWin32.Trojan.PSE.AA9MN3
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Hupigon.C97446
McAfeeArtemis!CC4A594CBE23
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Generic@AI.100 (RDML:z3qop/Mtq5fQAUQO7Huq3w)
IkarusTrojan.Win32.Agent
MaxSecureDropper.Dinwod.frindll
FortinetRiskware/FlyApplication
DeepInstinctMALICIOUS

How to remove VHO:HackTool.Win32.NetScanner?

VHO:HackTool.Win32.NetScanner removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment