Trojan

What is “Trojan.Win32.SchoolBoy.ahg”?

Malware Removal

The Trojan.Win32.SchoolBoy.ahg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.SchoolBoy.ahg virus can do?

  • Presents an Authenticode digital signature
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
eu.ntrsupport.com

How to determine Trojan.Win32.SchoolBoy.ahg?


File Info:

crc32: E44B0D43
md5: c2878b7a2e721a205d34f8470380cbd1
name: C2878B7A2E721A205D34F8470380CBD1.mlw
sha1: b8fc1686c3d3f3f6ab8472527fc37fd816d89e3a
sha256: dd2f9c5280d7772512e62e30f2de8ff249826345802e59d75e9fc7a176319b63
sha512: 69f5083abeef2599d20068eafb806998ab1d70d0ac9dbd00ed02eece47d958fa8807591d588238d44616758315ab0337aa23d563bfcd64841040e2c1a752542e
ssdeep: 49152:nkSocwLMkCVdCkHLKatuuC6uuH8RDcUePTl/n1Lvz7u:bwuBKatuuC6uu0gUoTTLu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002 - 2012. Net Transmit & Receive S.L.U. (NTRglobal). All rights reserved.
ProductVersion: 1, 4, 0, 20
FileDescription: NTRglobal Remote Control Executable
FileVersion: 1, 4, 0, 20
CompanyName: Net Transmit & Receive S.L.U. (NTRglobal).
Translation: 0x0c0a 0x04b0

Trojan.Win32.SchoolBoy.ahg also known as:

DrWebTrojan.DownLoader26.41969
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.SchoolBoy.ahg
TencentWin32.Trojan.Schoolboy.Sxed
TACHYONTrojan/W32.SchoolBoy.1740176
ZillyaBackdoor.RozenaCRTD.Win32.8855
McAfee-GW-EditionArtemis
JiangminTrojan.SchoolBoy.ar
Antiy-AVLTrojan/Win32.Staser
ZoneAlarmTrojan.Win32.SchoolBoy.ahg
McAfeeArtemis!C2878B7A2E72
VBA32Trojan.SchoolBoy
Qihoo-360Win32/Trojan.BO.faa

How to remove Trojan.Win32.SchoolBoy.ahg?

Trojan.Win32.SchoolBoy.ahg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment