Crack

HackTool.Win32.Binder.bs malicious file

Malware Removal

The HackTool.Win32.Binder.bs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What HackTool.Win32.Binder.bs virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Harvests information related to installed instant messenger clients
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine HackTool.Win32.Binder.bs?


File Info:

crc32: 94ADAB17
md5: 1172996f92030f921568ba8643650c69
name: 206911.jpg
sha1: ec361a03f9b0095dd92a29ef2794c0124c11361a
sha256: 33cce03d34bb9b8d014d5c7f640c4bd57d9c7fc4ae1f663447bc044ae8b6d17d
sha512: 4537eeec7ebd8dbef8feb3441a3bcddd89f74e88ea020e845085d1f19f25b654bfef4574ad283702edccfc9f055879e1dcdc2c622400025f30246b2489890214
ssdeep: 24576:9QWn8RZz/gMbER12GT3OcQcGfjeHi7YmJXFsoPvWZ:9YRZDgqER12GT3OcQcGbeHE5Fso3W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

HackTool.Win32.Binder.bs also known as:

BkavW32.GenericBinderLnr.Trojan
DrWebTrojan.MulDrop2.39589
MicroWorld-eScanGen:Variant.Binder.1
FireEyeGeneric.mg.1172996f92030f92
CAT-QuickHealVirTool.Vbinder.CO5
ALYacGen:Variant.Binder.1
MalwarebytesHackTool.Binder
VIPRETrojan-Dropper.Win32.Binder.bs (v)
AegisLabHacktool.Win32.Binder.lo77
K7AntiVirusTrojan ( 004babd11 )
BitDefenderGen:Variant.Binder.1
K7GWTrojan ( 004babd11 )
Cybereasonmalicious.f92030
TrendMicroTROJ_BINDER_FC1700C9.UVPA
BitDefenderThetaGen:NN.ZexaF.32250.KvW@am6!KDpG
CyrenW32/Backdoor.FVDJ-1096
SymantecSMG.Heur!gen
TotalDefenseWin32/Tnega.AGBZ
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Binder-6
GDataWin32.Trojan.Binder.A
KasperskyHackTool.Win32.Binder.bs
AlibabaHackTool:Win32/Binder.ec6f5e31
NANO-AntivirusTrojan.Win32.Stealer.ghgrrr
ViRobotTrojan.Win32.A.Swisyn.49120
RisingDropper.Binder!1.AEB1 (CLASSIC)
Ad-AwareGen:Variant.Binder.1
SophosMal/Fareit-V
ComodoTrojWare.Win32.TrojanDropper.Binder.cls@4m6ovz
F-SecureTrojan.TR/Injector.bqrfx
BaiduWin32.Trojan-Dropper.Binder.m
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
CMCHackTool.Win32.Binder!O
EmsisoftGen:Variant.Binder.1 (B)
IkarusTrojan.Win32.Dorv
F-ProtW32/Backdoor2.HKXU
JiangminHackTool.Binder.bh
WebrootW32.Trojan.Gen
AviraTR/Injector.bqrfx
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Kryptik
Endgamemalicious (high confidence)
ArcabitTrojan.Binder.1
SUPERAntiSpywareTrojan.Agent/Gen-Binder
ZoneAlarmHackTool.Win32.Binder.bs
MicrosoftVirTool:Win32/Vbinder.CO
AhnLab-V3HackTool/Win32.Vbinder.R12127
Acronissuspicious
McAfeeTrojan-FDDZ!1172996F9203
VBA32Binder.Celesty
CylanceUnsafe
ESET-NOD32Win32/TrojanDropper.Binder.NBH
TrendMicro-HouseCallTROJ_BINDER_FC1700C9.UVPA
YandexHackTool.Binder!IMtdREcP3/k
SentinelOneDFI – Malicious PE
MaxSecureHackTool.W32.Binder.bs
FortinetW32/Dropper.NBH!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Hacktool.4af

How to remove HackTool.Win32.Binder.bs?

HackTool.Win32.Binder.bs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment