Malware

Should I remove “Win32/Hijacker.T”?

Malware Removal

The Win32/Hijacker.T is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Hijacker.T virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32/Hijacker.T?


File Info:

crc32: 2EDAB534
md5: 0f2309afae0d4203caab42d54c4ca78a
name: 0F2309AFAE0D4203CAAB42D54C4CA78A.mlw
sha1: f019782d212e17a623d0179c781edbf4ad9dc96f
sha256: 6d6451dc8918a80d0ef518db270dbad20369d03af144884dd94fc92039d0e3fd
sha512: 995b790a6febb52179a21287cee2c04af6e911f9326a9a8d48ed7b61e3e8dc57027f2a71fcfd03ffbbf0dfff68ccbb4387006ab7e878ce196609a86f7c92ebcc
ssdeep: 6144:t4lvEt5KYkTzlGz9gOUb2GBqoOkR6loMnKXAOEBu5UAb9Fs5c2yApxP34872GvNX:B5K/lGRgOUqmq9kR6lhKXKB3a9FsqJKB
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright(C)2010-2020 WwW.DAYANXAI.ME
InternalName: version
FileVersion: 1, 5, 0, 475
CompanyName: x5927x773cx4ed4~x65ed x5206x4eabxff08Ananxff09
PrivateBuild: ImWatcher Hook Dll
LegalTrademarks: ImWatcher Hook Dll
Comments: ImWatcher Hook Dll
ProductName: ImWatcher Hook Dll
SpecialBuild: ImWatcher Hook Dll
ProductVersion: 1, 5, 0, 475
FileDescription: ImWatcher Hook Dll
OriginalFilename: version.dll
Translation: 0x0804 0x04b0

Win32/Hijacker.T also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Gamania.34950
CAT-QuickHealTrojan.IGENERIC
ALYacTrojan.GenericKD.34452155
CylanceUnsafe
ZillyaTrojan.Hijacker.Win32.754
SangforMalware
AlibabaTrojan:Win32/Hijacker.35850d18
K7GWTrojan ( 0056b28d1 )
K7AntiVirusTrojan ( 0056b28d1 )
TrendMicroTROJ_GEN.R002C0PIT20
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Hijacker.T
APEXMalicious
AvastWin32:Trojan-gen
BitDefenderTrojan.GenericKD.34452155
NANO-AntivirusTrojan.Win32.Gamania.hvpeoc
MicroWorld-eScanTrojan.GenericKD.34452155
Ad-AwareTrojan.GenericKD.34452155
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZedlaF.34298.wK8aaKhsHGhb
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.0f2309afae0d4203
EmsisoftTrojan.GenericKD.34452155 (B)
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Hijacker
MicrosoftTrojan:Win32/Ymacco.AA6D
ArcabitTrojan.Generic.D20DB2BB
AegisLabTrojan.Win32.Hijacker.4!c
GDataTrojan.GenericKD.34452155
McAfeeRDN/Generic.hbg
MAXmalware (ai score=81)
VBA32TrojanPSW.Gamania
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PIT20
YandexTrojan.Hijacker!J730tTgJMDQ
IkarusPUA.Hacktool.Hijacker
FortinetRiskware/Hijacker
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Hijacker.T?

Win32/Hijacker.T removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment