Trojan

What is “Trojan.Win32.BHO.btav”?

Malware Removal

The Trojan.Win32.BHO.btav is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.BHO.btav virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Installs itself for autorun at Windows startup
  • Attempts to create or modify a Browser Helper Object
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.BHO.btav?


File Info:

crc32: 031B874B
md5: aac934939eebe547eb0caab0746efeae
name: USBSetup.exe
sha1: 6e76ca5acb7813c68da6a249734c9017f9f5629f
sha256: 832a333089b60f28e766f7af6eeb8171d6074d03c1570210a7875e5f532f2e37
sha512: 4f2f1eae93525fa409fc813e32e2c5d27c15b7c77438702f4b5f861100fc22db915a274c2cd19072f5f1364536eb8fb82f1d1c559a1f1714e1083fcf7ec8dd46
ssdeep: 12288:suMYSz51U71T1PSoQirUJ296K3IjBUlU/D2tVB4p8CzK28:5dSz581PNQirUJy0VUi/K3Bi8K
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2010
InternalName: AutoInstall
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: AutoInstall x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: AutoInstall Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: AutoInstall.EXE
Translation: 0x0804 0x04b0

Trojan.Win32.BHO.btav also known as:

McAfeeGenericR-DBM!AAC934939EEB
CylanceUnsafe
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
TrendMicroTROJ_GEN.R002C0OFL18
NANO-AntivirusTrojan.Win32.DownLoad3.fbzkmy
SymantecTrojan.Gen
TrendMicro-HouseCallTROJ_GEN.R002C0OFL18
AvastWin32:Malware-gen
ClamAVWin.Trojan.Bho-8583
KasperskyTrojan.Win32.BHO.btav
TencentAdware.Win32.BHO.tte
DrWebTrojan.DownLoad3.1137
ZillyaTrojan.BHO.Win32.25440
McAfee-GW-EditionGenericR-DBM!AAC934939EEB
SophosMal/Generic-S
IkarusTrojan.Win32.BHO
CyrenW32/Trojan.MBLL-1173
JiangminTrojan/BHO.qna
WebrootW32.Malware.Gen
AviraTR/Agent.798720.364
Antiy-AVLTrojan/Win32.BHO
KingsoftWin32.Malware.Heur_Generic.A.(kcloud)
MicrosoftPUA:Win32/Presenoker
Endgamemalicious (high confidence)
ZoneAlarmTrojan.Win32.BHO.btav
VBA32Trojan.BHO
MAXmalware (ai score=98)
YandexTrojan.BHO!n1yd5yOrxkA
FortinetW32/BHO.BTAV!tr
AVGWin32:Malware-gen

How to remove Trojan.Win32.BHO.btav?

Trojan.Win32.BHO.btav removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment