Malware

About “Win32/Hematite.A” infection

Malware Removal

The Win32/Hematite.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Hematite.A virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Hematite.A?


File Info:

name: 8BF1EE6F2E3D76EA32E5.mlw
path: /opt/CAPEv2/storage/binaries/dcbe469a364b32ae358e9ed7f3563318947849ad5e1cc5899e84665c01502389
crc32: 28E7F9F7
md5: 8bf1ee6f2e3d76ea32e53e52cb8e3bfa
sha1: 366b77f88e976e608e586f7ac79e4eb4ff2197a8
sha256: dcbe469a364b32ae358e9ed7f3563318947849ad5e1cc5899e84665c01502389
sha512: c1d05379f91ba84cd9ebfd92f4b50a56f56995902c7a2337ae94e89c0957e5a09a666d10a952925431a8564fc2c47816a224f6979dce59892a8dc5353d021f38
ssdeep: 6144:gVzjPjjJmJPUcjy022w0XzJchzmUr29UYuo2LcYeFjdgPzNt9opQBg+Y/Z:0hI9uTpaJSzmguUYuo2LUmoTX/Z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18EC4961262E54128F0F33A70697823350B7B7CA1AA3DC28F419855AD5EF3E80ED757A7
sha3_384: e90c59685b1fe7ebbe15db919364cbfd856d890a71b13060fad30a95f37121b25d2b2e23e0e66efc3928a3aebdc76b13
ep_bytes: b8001100002be087dbbe0004000187db
timestamp: 2008-04-13 18:33:39

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Auto Check Utility
FileVersion: 5.1.2600.5512 (xpsp.080413-2111)
InternalName: AutoChk
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: AutoChk.Exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.5512
Translation: 0x0409 0x04b0

Win32/Hematite.A also known as:

BkavW32.AIDetectMalware
DrWebWin32.Siggen.29
MicroWorld-eScanTrojan.GenericKDZ.102326
CAT-QuickHealW32.Infector.A5
SkyhighBehavesLike.Win32.HWorld.hm
McAfeeW32/HWorld!8BF1EE6F2E3D
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 00508e1d1 )
K7GWVirus ( 00508e1d1 )
Cybereasonmalicious.f2e3d7
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Hematite.A
APEXMalicious
AvastWin32:Evo-gen [Trj]
KasperskyHEUR:Trojan.Win32.Ekstak.gen
BitDefenderTrojan.GenericKDZ.102326
NANO-AntivirusVirus.Win32.Infector.emtrum
TencentVirus.Win32.Infector.ya
EmsisoftTrojan.GenericKDZ.102326 (B)
GoogleDetected
F-SecureTrojan.TR/Agent.qhtpx
BaiduWin32.Trojan.Agent.awj
VIPRETrojan.GenericKDZ.102326
FireEyeGeneric.mg.8bf1ee6f2e3d76ea
SophosW32/HWorld-A
SentinelOneStatic AI – Malicious PE
VaristW32/Trojan.DXT.gen!Eldorado
AviraTR/Agent.qhtpx
MAXmalware (ai score=84)
Antiy-AVLVirus/Win32.Infector.gen
MicrosoftVirus:Win32/Hematite.A
XcitiumVirus.Win32.Hematite.A@77ycil
ArcabitTrojan.Generic.D18FB6
ZoneAlarmHEUR:Trojan.Win32.Ekstak.gen
GDataTrojan.GenericKDZ.102326
CynetMalicious (score: 100)
AhnLab-V3Virus/Win.Hworld.R556194
VBA32Virus.Hematite
ALYacTrojan.GenericKDZ.102326
TACHYONVirus/W32.Hematite
Cylanceunsafe
RisingVirus.Hematite!1.EF53 (CLASSIC)
IkarusTrojan.Agent
MaxSecureVirus.W32.Infector.Gen
FortinetW32/Agent.D17
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirus:Win/HelloWorld.a(dyn)

How to remove Win32/Hematite.A?

Win32/Hematite.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment