Crack

About “Win32/HackTool.Equation.W” infection

Malware Removal

The Win32/HackTool.Equation.W is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/HackTool.Equation.W virus can do?

  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Locates and dumps memory from the lsass.exe process indicative of credential dumping

How to determine Win32/HackTool.Equation.W?


File Info:

crc32: 417F9D2C
md5: 0d5f196349de5ab4bf12d532f8f6d425
name: c.exe
sha1: 9feea6eb062c627963e038f053f75da9537ffe13
sha256: 320636740ae47f6c7ecea01a054bd67bf4dec0a9e74500fb90295bbfcd0aa80b
sha512: d36fc2731d54bc752d3e60e9eeb9acb94273a0562cb38e2f99221848610965cc82efb9f1973dfaf3e25d09847c37ac5963c93f4c8c595fc9ce895dc63e32dd70
ssdeep: 98304:I3AdiNQvJDG25zSiRXscMqUBk5SqtiTlMqiojV3i2S7:9gqS2vRXs85SnhrV3w7
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Win32/HackTool.Equation.W also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Variant.Ulise.85448
FireEyeGeneric.mg.0d5f196349de5ab4
Qihoo-360Win32/Trojan.1a6
McAfeeArtemis!0D5F196349DE
CylanceUnsafe
SangforMalware
K7AntiVirusHacktool ( 005444c71 )
BitDefenderGen:Variant.Ulise.85448
K7GWHacktool ( 005444c71 )
Cybereasonmalicious.b062c6
TrendMicroRansom.Win32.SATANA.A
BitDefenderThetaGen:NN.ZexaF.34090.ppqaa8wDFPci
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/HackTool.Equation.W
TrendMicro-HouseCallRansom.Win32.SATANA.A
AvastWin32:Malware-gen
GDataGen:Variant.Ulise.85448
KasperskyTrojan.Win32.Shelma.asvi
AlibabaTrojan:Win32/Shelma.a7aa0a32
AegisLabHacktool.Win32.ShadowBrokers.3!c
TencentWin32.Trojan.Shelma.Gvv
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ulise.85448 (B)
F-SecureTrojan.TR/Equation.ulkkx
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PUPXAX.wc
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
CMCVirus.Win32.Sality!O
SophosMal/Generic-S
APEXMalicious
JiangminTrojan.Crypmod.vn
AviraTR/Equation.ulkkx
Antiy-AVLTrojan[Ransom]/Win32.Crypmod
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ulise.D14DC8
AhnLab-V3Malware/Win32.Generic.C3550003
ZoneAlarmTrojan.Win32.Shelma.asvi
Acronissuspicious
ALYacGen:Variant.Ulise.85448
MAXmalware (ai score=100)
Ad-AwareGen:Variant.Ulise.85448
PandaTrj/CI.A
RisingTrojan.Wacatac!8.10C01 (TFE:5:EkOpCQCKMMU)
eGambitUnsafe.AI_Score_91%
FortinetW32/Crypmod.ADCS!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/HackTool.Equation.W?

Win32/HackTool.Equation.W removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment