Backdoor

Backdoor:Win32/Trochil.A.dll!dha removal tips

Malware Removal

The Backdoor:Win32/Trochil.A.dll!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Trochil.A.dll!dha virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor:Win32/Trochil.A.dll!dha?


File Info:

crc32: EC546C41
md5: bd17c24dc4521e1acf5e606de6f9362e
name: Update.exe
sha1: c55e60c937531ff2c782cb3d7df459fadd7ace38
sha256: 7979416b5226d888d6a3c57d1465c217848ebee2863400a26448f87ec6613505
sha512: 5e8953303eb16f3f09a68155422e6156a6006f43824f25ffbbf52dced6c68ca768ecd2a7a71d79ffb9f511de34d3f43cefb75e1eb4c4c020e9d783fad8fe2d71
ssdeep: 6144:NsF9dwKB3KYbmCfKypyv1nSsI4HWwfZImTEP+AUP5PyEjKdWdCqQwx:Am2bLKMyv1nSsI4HWcTEP+AE3Qwx
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Backdoor:Win32/Trochil.A.dll!dha also known as:

DrWebBackDoor.Siggen2.2683
McAfeeArtemis!BD17C24DC452
MalwarebytesBackdoor.Agent
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.NSIS.Agent.m!c
K7AntiVirusTrojan ( 0050a14d1 )
BitDefenderTrojan.GenericKD.43383142
K7GWTrojan ( 0050a14d1 )
Cybereasonmalicious.937531
ArcabitTrojan.Generic.D295F966
CyrenW32/Trojan.XQGV-2299
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Korplug.KA
TrendMicro-HouseCallTROJ_GEN.R002H0CFL20
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyBackdoor.NSIS.Agent.r
AlibabaBackdoor:Win32/Korplug.41d5c983
ViRobotTrojan.Win32.S.Agent.331919
MicroWorld-eScanTrojan.GenericKD.43383142
Ad-AwareTrojan.GenericKD.43383142
EmsisoftTrojan.GenericKD.43383142 (B)
ComodoMalware@#ccaw5d1r0qda
F-SecureHeuristic.HEUR/AGEN.1112152
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.bd17c24dc4521e1a
SophosMal/Generic-S
IkarusTrojan.Win32.Korplug
AviraHEUR/AGEN.1112152
MicrosoftBackdoor:Win32/Trochil.A.dll!dha
ZoneAlarmBackdoor.NSIS.Agent.r
ALYacTrojan.GenericKD.43383142
MAXmalware (ai score=88)
VBA32Backdoor.Agent
CylanceUnsafe
APEXMalicious
TencentNsis.Backdoor.Agent.Pfsx
GDataTrojan.GenericKD.43383142
WebrootW32.Trojan.Gen
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Backdoor.4f2

How to remove Backdoor:Win32/Trochil.A.dll!dha?

Backdoor:Win32/Trochil.A.dll!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment