Worm

How to remove “Worm:Win32/Hacul.A”?

Malware Removal

The Worm:Win32/Hacul.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Hacul.A virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Arabic (Algeria)
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Worm:Win32/Hacul.A?


File Info:

crc32: 0869E13A
md5: b105f26b44ce6f47a7149e9dd7a1fb4b
name: B105F26B44CE6F47A7149E9DD7A1FB4B.mlw
sha1: 05196a50c54c1c04d420f3dd3ddb2989f690bf01
sha256: d0cf80c143fd2b5f4c713104f6e4c746448c6bdc1715a83a66c410641c77a22e
sha512: 477a355336a55c145a6de7d0f6baed7206e7786c9014ba794c09a76385aab34e3d1133f732a995b2e3500917568c2601be434da67c4baf81ac4aefd112a50d6c
ssdeep: 12288:BbNcT/oyoXDw1VXqNTwqKYAIuFCHrTpcCXCdTm2cLdTyKMO5RLJI/8fpVhSo9CS:Bpcjobw1V6iJlFCHBLmwLdTyKD1pBC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm:Win32/Hacul.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop3.45378
CynetMalicious (score: 100)
CAT-QuickHealRansom.Blocker.7723
ALYacTrojan.Autorun.BCP
CylanceUnsafe
ZillyaDropper.Dapato.Win32.10775
SangforVirus_Suspicious.Win32.Sality.bh
CrowdStrikewin/malicious_confidence_100% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b44ce6
CyrenW32/Backdoor.ASLY-8302
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/AutoRun.Delf.MH
APEXMalicious
AvastWin32:AutoRun-CRM [Wrm]
ClamAVWin.Trojan.Autorun-12582
KasperskyTrojan-Ransom.Win32.Blocker.aepm
BitDefenderTrojan.Autorun.BCP
NANO-AntivirusTrojan.Win32.Blocker.djpuzj
MicroWorld-eScanTrojan.Autorun.BCP
Ad-AwareTrojan.Autorun.BCP
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZelphiF.34088.ZGZ@aCE7hHgG
VIPREVirus.Win32.Sality.at (v)
TrendMicroMal_Otorun5
McAfee-GW-EditionBehavesLike.Win32.Virus.ch
FireEyeGeneric.mg.b105f26b44ce6f47
EmsisoftTrojan.Autorun.BCP (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Dapato.jll
AviraWORM/Autorun.vctqx
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.19AF87
MicrosoftWorm:Win32/Hacul.A
ArcabitTrojan.Autorun.BCP
GDataTrojan.Autorun.BCP
AhnLab-V3Trojan/Win32.Blocker.R89476
McAfeeArtemis!B105F26B44CE
MAXmalware (ai score=88)
VBA32TrojanDropper.Dapato
MalwarebytesSality.Virus.FileInfector.DDS
PandaTrj/CI.A
TrendMicro-HouseCallMal_Otorun5
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.MH!worm
AVGWin32:AutoRun-CRM [Wrm]
Qihoo-360Win32/Ransom.Blocker.HwUBUOIA

How to remove Worm:Win32/Hacul.A?

Worm:Win32/Hacul.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment