PUA

Win32:HideProc-N [PUP] removal tips

Malware Removal

The Win32:HideProc-N [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:HideProc-N [PUP] virus can do?

  • Creates RWX memory
  • Loads a driver
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32:HideProc-N [PUP]?


File Info:

crc32: 40636C1C
md5: 8d41ba6837d6f1fa4c0893d7dad56dfb
name: 8D41BA6837D6F1FA4C0893D7DAD56DFB.mlw
sha1: da390801d3aca3ca32e944ec35ec08a24d480507
sha256: 214a2dc40e363df0c4bfbf9c9c7e138c128e719a31391fe2b2c88f7f2d2528b3
sha512: f25e0e9eced4a5987873c9af76b3323525ab6ebcca6449ae9adc4092279b6fb952ef41fe865ea8dc92651240f8e531ba9743a2e0385f4c6357b6dc1a3a06f219
ssdeep: 49152:aI9BsBE9UZM4OKsB8X4VhKJ4OKsB8X4VjsB8X4cE9UMsB8X4VjsB8X4cE9Um:aI9BsiU+d8Xxd8Xv8XWU78Xv8XWUm
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32:HideProc-N [PUP] also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTool.HideProc.27
ClamAVWin.Trojan.Hideproc-77
ALYacGen:Variant.Fugrafa.5885
CylanceUnsafe
ZillyaTrojan.Delf.Win32.52545
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0008550a1 )
K7AntiVirusTrojan ( 0008550a1 )
CyrenW32/Delf.IQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.NZQ
APEXMalicious
AvastWin32:HideProc-N [PUP]
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Banload.aalpj
BitDefenderGen:Variant.Fugrafa.5885
NANO-AntivirusRiskware.Win32.HideProc.crvalg
MicroWorld-eScanGen:Variant.Fugrafa.5885
TencentMalware.Win32.Gencirc.10b87824
Ad-AwareGen:Variant.Fugrafa.5885
SophosTroj/Ghetifuh-A
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZelphiF.34236.@xZ@aOrrWxbb
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRTKT_HIDEPROC.BB
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
FireEyeGeneric.mg.8d41ba6837d6f1fa
EmsisoftGen:Variant.Fugrafa.5885 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Banload.akge
AviraTR/Rootkit.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.112E4
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmTrojan-Downloader.Win32.Banload.aalpj
GDataGen:Variant.Fugrafa.5885
AhnLab-V3Trojan/Win.Banload.R447588
Acronissuspicious
McAfeeGenericRXAA-AA!8D41BA6837D6
MAXmalware (ai score=84)
VBA32BScope.TrojanDownloader.Banload
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
TrendMicro-HouseCallRTKT_HIDEPROC.BB
RisingRootKit.Win32.HideProc.l (CLASSIC)
IkarusTrojan.Win32.Buzus
MaxSecureTrojan.Malware.500016.susgen
FortinetW32/Delf.NZQ!tr
AVGWin32:HideProc-N [PUP]

How to remove Win32:HideProc-N [PUP]?

Win32:HideProc-N [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment