Malware

Should I remove “Win32/PSW.Hukle.15”?

Malware Removal

The Win32/PSW.Hukle.15 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Hukle.15 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/PSW.Hukle.15?


File Info:

name: A4CDACFAA1DF1CF00586.mlw
path: /opt/CAPEv2/storage/binaries/1e9802e5471f2ffdefdd0287641f72ad685fd8d40a02d62b0c34b8cddd6084e9
crc32: BEEF06B6
md5: a4cdacfaa1df1cf0058663294ad1cd1c
sha1: 746d24c1f81bce234f21a633b313fcbdb099b425
sha256: 1e9802e5471f2ffdefdd0287641f72ad685fd8d40a02d62b0c34b8cddd6084e9
sha512: 6c8ee4ec84817204dd4eda9c2eb4cdae58ec23782377bfba70a87524471a6ffee9770afa7d96089600a83c8dfc7785b0fef05a36fe935b94a91ba60058eee6e3
ssdeep: 3072:ZPihvkLckJmTvhQGAQhuFixV/Q/xlElT6Lgyqqx:ZP6k42yXAQhuOQZ+ljy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T139D3F185B340FF96C5B84B36A987CBC3532A7CB0AB1653E322D97ADF6C771412D16242
sha3_384: 0a0da963d2d92b326b6961eb2dd3113121bf1a29c70a77da6b5f6b858876c7b3a7ae5abe119157d3497ac825d49631f1
ep_bytes: 60be008042008dbe0090fdff5783cdff
timestamp: 2002-05-10 01:56:45

Version Info:

Comments:
CompanyName: mage of Mielikki
FileDescription: Hiddukel v1.5
FileVersion: 1, 5, 0, 0
InternalName: Hiddukel
LegalCopyright: Copyright 2002
LegalTrademarks:
OriginalFilename: Hiddukel.exe
PrivateBuild:
ProductName: Hiddukel
ProductVersion: 1, 5, 0, 0
SpecialBuild:
Translation: 0x0804 0x04b0

Win32/PSW.Hukle.15 also known as:

BkavW32.Common.9E45DDBA
LionicTrojan.Win32.Hukle.4!c
SkyhighHiddukel.a
McAfeeHiddukel.a
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Hukle.Win32.83
SangforInfostealer.Win32.Hukle.Vw9w
K7AntiVirusPassword-Stealer ( 0055e3dc1 )
AlibabaTrojanPSW:Win32/Hukle.53062ce8
K7GWPassword-Stealer ( 0055e3dc1 )
Cybereasonmalicious.1f81bc
SymantecTrojan.Zbot
ESET-NOD32Win32/PSW.Hukle.15
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Hukle.15
NANO-AntivirusTrojan.Win32.Hukle.frss
TencentWin32.Trojan-QQPass.QQRob.Zmhl
TACHYONTrojan-PWS/W32.Hukle.241664
DrWebTrojan.PWS.Hukle.138
TrendMicroTROJ_HIDDUKEL.A
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.Hukle
JiangminTrojan/Hiddukel.15
WebrootW32.Trojan.Trojan-PWS-Hukle
GoogleDetected
Antiy-AVLTrojan[PSW]/Win32.Hukle
XcitiumTrojWare.Win32.PSW.Hukle.15@18t8
MicrosoftTrojan:Win32/DSSDetection
ViRobotTrojan.Win32.PSWHukle.130048
ZoneAlarmTrojan-PSW.Win32.Hukle.15
GDataWin32.Trojan.Agent.H2E80X
VaristW32/Trojan.QAUJ-2515
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32TrojanPSW.Hukle
Cylanceunsafe
TrendMicro-HouseCallTROJ_HIDDUKEL.A
RisingTrojan.Hiddukel (CLOUD)
YandexTrojan.PWS.Hukle!v/klMEXVkBs
FortinetW32/Hiddukel.A!tr
PandaTrojan Horse
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/PSW.Hukle.15?

Win32/PSW.Hukle.15 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment