Malware

What is “Win32:Huhk-C [Wrm]”?

Malware Removal

The Win32:Huhk-C [Wrm] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Huhk-C [Wrm] virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics

How to determine Win32:Huhk-C [Wrm]?


File Info:

name: 0222F40E8426840EB804.mlw
path: /opt/CAPEv2/storage/binaries/d022d1576578ee8bc9a476a3eb8ee1d5e5785d6e39cb5989e6e49c487a213dfe
crc32: 609BF2CB
md5: 0222f40e8426840eb804271d82ba0731
sha1: 623601974bf4f1375859faab117c76edf215ae06
sha256: d022d1576578ee8bc9a476a3eb8ee1d5e5785d6e39cb5989e6e49c487a213dfe
sha512: 30c5ee223292e40efcef744198266c703d1bb4416cfb4003d5671ccac851052f4d84f122ee32f3086c4e2f7bfd79d280151c8b8f110bea4ab8aa4d8315e2e718
ssdeep: 384:ObzxErmtdcnL4ZE1hOuSZNtEwwa4w55iHbrsPba2/Le1VN4nf5HV:ObgMcUYUuMWpab5iHft2zeqRHV
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E9B24A47AFD60876E7C2C7300EAAD7BDC726B4E166356E13CB00DD32292255CD97423A
sha3_384: f708745c24aa85dc56385a00ea3d4847ad855744dc73c1184843d2579853c6e1c2a19e6a813a4bd42e763bbf38f1f1e9
ep_bytes: 558bec6aff68e8304000681022400064
timestamp: 1970-02-14 10:11:58

Version Info:

Comments:
CompanyName: Tencent Technology (Shenzhen) Company Limited
FileDescription: KeyCrypt Driver Installer
FileVersion: 1, 0, 0, 1
InternalName: ServiceInstaller
LegalCopyright: Copyright (c) 1998 - 2007 TENCENT Inc. All rights reserved.
LegalTrademarks:
OriginalFilename: ServiceInstaller.exe
PrivateBuild:
ProductName: ServiceInstaller
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Win32:Huhk-C [Wrm] also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Generic.l3hF
FireEyeGeneric.mg.0222f40e8426840e
SkyhighArtemis!Trojan
McAfeeArtemis!0222F40E8426
Cylanceunsafe
SangforTrojan.Win32.SilverFox.swkbf
AlibabaBackdoor:Win32/PcClient.58916104
Elasticmalicious (high confidence)
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
AvastWin32:Huhk-C [Wrm]
F-SecureMalware.W32/Huhk.AA
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.Agent
GoogleDetected
AviraW32/Huhk.AA
KingsoftWin32.Infected.AutoInfector.a
XcitiumWorm.Win32.Huhk.c5@1bslvl
ZoneAlarmUDS:DangerousObject.Multi.Generic
VBA32BScope.Backdoor.Agent
MAXmalware (ai score=87)
PandaTrj/Genetic.gen
YandexWin32.Huhk.A
MaxSecureTrojan.Malware.4387980.susgen
AVGWin32:Huhk-C [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirus:Win/Huhk.AA

How to remove Win32:Huhk-C [Wrm]?

Win32:Huhk-C [Wrm] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment