Worm

Worm:Win32/Hamweq.A removal instruction

Malware Removal

The Worm:Win32/Hamweq.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Hamweq.A virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Hamweq.A?


File Info:

name: 68AA6365ECA558B359C9.mlw
path: /opt/CAPEv2/storage/binaries/a4992145e80ef4802eec0f7432febaa79e8eeaf6c516474c3c4c897787e67a07
crc32: C0412D2A
md5: 68aa6365eca558b359c90a92b598c7f2
sha1: 3fc6db6f3410747d69999b68542b9f99a4a599d1
sha256: a4992145e80ef4802eec0f7432febaa79e8eeaf6c516474c3c4c897787e67a07
sha512: 710689d807fafb7a0aa00bfe7dfca53ad2345771237a56da3b3cc59f6328c677a325158322fc84b382eb5e6f0db67bc61cedc28b19c116b12730a869dfd3ecb0
ssdeep: 384:1Xv6shFf/3VDxU3mJW6+FN+Bn9iyg4Ay:R64Ff/3VDxU3d6+n+J+1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12142D5C394419224D1324972379AFB7A5F0F6D733382F5A9369274BD04B30EDA96A307
sha3_384: 97ed4d8fd9d13ec633943eb4c41f38a497ae545d9bacc75a892ac39ac9eab5d80b3455aa5a66e2cc9b3d704636f69ac2
ep_bytes: 558bec81ecdc05000083a5ecfdffff00
timestamp: 2008-12-25 14:21:46

Version Info:

0: [No Data]

Worm:Win32/Hamweq.A also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.AutoRun.l4bO
MicroWorld-eScanBackdoor.Hamweq.B
FireEyeGeneric.mg.68aa6365eca558b3
CAT-QuickHealTrojan.Generic.5838
SkyhighW32/Hamweq.worm.f
McAfeeW32/Hamweq.worm.f
Cylanceunsafe
VIPREBackdoor.Hamweq.B
K7AntiVirusP2PWorm ( 000116c21 )
AlibabaWorm:Win32/AutoRun.bba816a9
K7GWP2PWorm ( 000116c21 )
Cybereasonmalicious.f34107
VirITTrojan.Win32.Generic.NY
SymantecW32.IRCBot
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.KS
APEXMalicious
KasperskyWorm.Win32.AutoRun.frb
BitDefenderBackdoor.Hamweq.B
NANO-AntivirusTrojan.Win32.Hamweq.gkgk
SUPERAntiSpywareWorm.AutoRun/Variant
AvastWin32:WormX-gen [Wrm]
TencentWin32.Worm.Autorun.Gflw
TACHYONBackdoor/W32.Hamweq.12800
EmsisoftBackdoor.Hamweq.B (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebBackDoor.Ddoser.131
ZillyaWorm.AutoRun.Win32.62051
TrendMicroWORM_HAMWEQ.SMC
Trapminesuspicious.low.ml.score
SophosW32/Autoham-Fam
SentinelOneStatic AI – Malicious PE
GDataBackdoor.Hamweq.B
JiangminWorm/AutoRun.jtv
WebrootW32.Worm.F
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Backdoor.Y.gen!Eldorado
Antiy-AVLWorm/Win32.AutoRun
KingsoftWin32.Troj.AutoRunT.ac.13552
XcitiumMalware@#10se409rlvpti
ArcabitBackdoor.Hamweq.B
ViRobotWorm.Win32.Autorun.12800.F
ZoneAlarmWorm.Win32.AutoRun.frb
MicrosoftWorm:Win32/Hamweq.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C63095
BitDefenderThetaAI:Packer.3C552D0F1B
ALYacBackdoor.Hamweq.B
MAXmalware (ai score=100)
VBA32Worm.Autorun
MalwarebytesMalware.AI.2412001528
PandaGeneric Malware
ZonerTrojan.Win32.5682
TrendMicro-HouseCallWORM_HAMWEQ.SMC
RisingTrojan.Win32.Nodef.kcb (CLASSIC)
YandexTrojan.GenAsa!zOG16w/sGHs
IkarusWorm.Win32.AutoRun
FortinetW32/AutoRun.EJS!worm
AVGWin32:WormX-gen [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Worm:Win32/Hamweq.A?

Worm:Win32/Hamweq.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment