Malware

Win32/Hematite.D removal guide

Malware Removal

The Win32/Hematite.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Hematite.D virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Hematite.D?


File Info:

name: 10DE427F9D1B4BC777E8.mlw
path: /opt/CAPEv2/storage/binaries/a2b2225be4740363627a6bd8accac59dbe7a27b60bda80d458465450315ae565
crc32: 0F078563
md5: 10de427f9d1b4bc777e82ddf492f02d0
sha1: dcd7c9e67193f11c5da6b7ee059e3d1f7a6e345d
sha256: a2b2225be4740363627a6bd8accac59dbe7a27b60bda80d458465450315ae565
sha512: 2be59618db66e05c6b7e5ef00f7d6df469ead728372a4e4866244eb1d4d7453489435759516402f43d3c07de108271655e362b69874a742ba45cd083708785a0
ssdeep: 6144:ZdTljJ2M4qdiG6wKt6wVXHgQ3Zcfhfi4Che+/xmbas2E++P0PzJCwF4PimfhR:gyV6wKtVXHl0h64Clxmbas2JG7h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1C4961262E54128F4F33A70697823344B7BBCA1AA3DC68F4198559D5EF3E80ED707A7
sha3_384: 016763cb340b05a00cd135b05c8ecaf12d09cc05351f373bf710ef41f2486f42bbfa594516f9d7c94b4ca662c520bd56
ep_bytes: b8001100002be0be0004000190545ffc
timestamp: 2008-04-13 18:33:39

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Auto File System Conversion Utility
FileVersion: 5.1.2600.5512 (xpsp.080413-2111)
InternalName: autoconv
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: AUTOCONV.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.5512
Translation: 0x0409 0x04b0

Win32/Hematite.D also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CAT-QuickHealW32.Infector.A5
SkyhighBehavesLike.Win32.HWorld.hm
McAfeeW32/HWorld!10DE427F9D1B
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 00508e1d1 )
K7GWVirus ( 00508e1d1 )
ESET-NOD32a variant of Win32/Hematite.D
APEXMalicious
NANO-AntivirusVirus.Win32.Infector.emtrum
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.Infector.ya
TACHYONVirus/W32.Hematite
DrWebWin32.Siggen.29
FireEyeGeneric.mg.10de427f9d1b4bc7
SophosW32/HWorld-A
IkarusTrojan.Agent
GoogleDetected
VaristW32/Hematite.A!Generic
Antiy-AVLGrayWare/Win32.Kryptik.hematite
MicrosoftVirus:Win32/Hematite.A
XcitiumVirus.Win32.Hematite.A@77ycil
CynetMalicious (score: 100)
AhnLab-V3Virus/Win.Hworld.R556194
VBA32Win32.Virus.Unknown.Heur
Cylanceunsafe
RisingVirus.Hematite!1.EF53 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureVirus.W32.Infector.Gen
FortinetW32/Agent.D17
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Hematite.D?

Win32/Hematite.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment