Trojan

Trojan.Win32.Bayrob.ilor removal

Malware Removal

The Trojan.Win32.Bayrob.ilor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Bayrob.ilor virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Starts servers listening on 127.0.0.1:0
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Connects to an IRC server, possibly part of a botnet
  • Unusual version info supplied for binary

Related domains:

k6239847.lib
bdns.nu
bdns.at
bdns.co

How to determine Trojan.Win32.Bayrob.ilor?


File Info:

crc32: 93230662
md5: c9815c10e4423ee8529ee28628c7b192
name: taskhost.exe
sha1: 8422af807a8ce012b86cfb7a90b55bc82eb961e7
sha256: 29233f9b14ccd56db1b00f51155df7e59ca819fceb4f5b74ded3f16b2daed67c
sha512: b3f61301ca24769d8dcd329b7560b710caa0745da74e5ac513faae71b5b32476dd60786e53d3b06446101833252379a8d58d91f564b1b505ff15837b71b5e039
ssdeep: 12288:wZqzSIUAY/B6WIXFX/jElF4R4lPm7JQoSvdroVcQpiICek2a+JAKdpq:wZqzSZAD7qF4Rkm79IroVcQIzeLa+JN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: 22222222
FileVersion: 6.1.7600.16385
CompanyName: TODO:
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Host Process for Windows Services
OriginalFilename: taskhost.exe
Translation: 0x0009 0x04b0

Trojan.Win32.Bayrob.ilor also known as:

MicroWorld-eScanTrojan.GenericKD.33806056
ALYacTrojan.GenericKD.33806056
MalwarebytesTrojan.Crypt
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Bayrob.4!c
SangforMalware
BitDefenderTrojan.GenericKD.33806056
K7GWTrojan ( 0056621d1 )
ArcabitTrojan.Generic.D203D6E8
TrendMicroTROJ_GEN.R002C0PEA20
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ABVO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Bayrob.ilor
AlibabaTrojan:Win32/Bayrob.99b711b7
RisingTrojan.Agent!8.B1E (CLOUD)
Ad-AwareTrojan.GenericKD.33806056
EmsisoftTrojan.GenericKD.33806056 (B)
ComodoMalware@#21ywayu64nt8x
F-SecureAdware.ADWARE/FileFinder.Gen7
Invinceaheuristic
McAfee-GW-EditionRDN/Generic.tfr
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
AviraADWARE/FileFinder.Gen7
FortinetRiskware/Agent
Antiy-AVLTrojan/Win32.Bayrob
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/CryptInject!MTB
ZoneAlarmTrojan.Win32.Bayrob.ilor
McAfeeRDN/Generic.tfr
MAXmalware (ai score=86)
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PEA20
TencentWin32.Trojan.Bayrob.Szuv
SentinelOneDFI – Malicious PE
GDataTrojan.GenericKD.33806056
BitDefenderThetaGen:NN.ZexaF.34108.PC0@aukmgxgk
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.7a8

How to remove Trojan.Win32.Bayrob.ilor?

Trojan.Win32.Bayrob.ilor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment