Crack Virus

Virus:Win32/Patchload.A removal

Malware Removal

The Virus:Win32/Patchload.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Patchload.A virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Patchload.A?


File Info:

name: 07685F2DFEA1556AD912.mlw
path: /opt/CAPEv2/storage/binaries/f4bc5d1609a25b9b24e4b2cc39b81d0e0cec688b6efd856b546d5c4fbdb43d81
crc32: B54F2558
md5: 07685f2dfea1556ad912d9192e35b3c1
sha1: 827dabb72ae85a74c890b00ebd4d7e62c7410c46
sha256: f4bc5d1609a25b9b24e4b2cc39b81d0e0cec688b6efd856b546d5c4fbdb43d81
sha512: d9e9d7ee5d316d252a6efaf366f9d18993f76ee2830167e21114d9e3d6ada003f56f8af6c85fc5c2bc36bb16db715b0686c03b566dcaafda870205fbdcf7aac3
ssdeep: 6144:UuwM3I4nEYm2WLZz9PGGISkraoIX4NRZLLd/BZpymJZBS+tSfEwv5wyM:ykI4nJmRz9PGGjkrgoN9Ppymfkn
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T174742A94B863C0E4F5A63270812D7EB4F1DDDFA994FEBA0B15C8DCA52A21840F725D1E
sha3_384: 6bf873e79bfc95ff1ebda64f763c1be000dd0015b47a1df9a82d7e9dcf6f247e5e1bb0c5448dbc798823a1496123e6d2
ep_bytes: 68583f05009058e80000000090588b50
timestamp: 2008-04-14 02:13:26

Version Info:

CompanyName: Microsoft Corporation
FileDescription: DirectSound
FileVersion: 5.3.2600.5512 (xpsp.080413-0845)
InternalName: DirectSound
LegalCopyright: (C) Microsoft Corporation. All rights reserved.
OriginalFilename: dsound.dll
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 5.3.2600.5512
Translation: 0x0804 0x04b0

Virus:Win32/Patchload.A also known as:

BkavW32.PatchloadTN.PE
LionicTrojan.Win32.Patched.laXu
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Gamania.23481
MicroWorld-eScanTrojan.Patched.FL
FireEyeTrojan.Patched.FL
CAT-QuickHealTrojan.Patched.HL
SkyhighW32/PatchLoad
McAfeeArtemis!07685F2DFEA1
Cylanceunsafe
VIPRETrojan.Patched.FL
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Patchload.1a936a60
K7GWTrojan ( 000e43fb1 )
K7AntiVirusTrojan ( 000e43fb1 )
SymantecTrojan.Gen.6
ESET-NOD32Win32/Patched.EW.Gen
CynetMalicious (score: 99)
Paloaltogeneric.ml
KasperskyTrojan.Win32.Patched.hl
BitDefenderTrojan.Patched.FL
NANO-AntivirusTrojan.Win32.Gamania.dgfupa
EmsisoftTrojan.Patched.FL (B)
F-SecureTrojan.TR/Crypt.EPACK.Gen2
BaiduWin32.Virus.Loader.d
ZillyaTrojan.Patched.Win32.8602
TrendMicroPE_PATCHLOAD.DRL
SophosMal/Generic-S
JiangminWin32/PatchFile.dk
WebrootW32.Malware.Downloader
VaristW32/Patched.K.gen!Eldorado
AviraTR/Crypt.EPACK.Gen2
KingsoftWin32.DsLoader.ip.367616
MicrosoftVirus:Win32/Patchload.A
XcitiumTrojWare.Win32.Patched.I@1lxkab
ArcabitTrojan.Patched.FL
ZoneAlarmTrojan.Win32.Patched.hl
GDataWin32.Trojan.Patched.IB
GoogleDetected
AhnLab-V3Win-Trojan/Patched.S
ALYacTrojan.Patched.FL
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
TrendMicro-HouseCallPE_PATCHLOAD.DRL
TencentVirus.Win32.Patched.f
IkarusTrojan.Win32.Patched
MaxSecureVirus.Patched.HL
FortinetW32/Patched.AH!tr
PandaW32/Patched.T
alibabacloudVirus:Win/Patchload!patchload_d.PD

How to remove Virus:Win32/Patchload.A?

Virus:Win32/Patchload.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment