Trojan

About “TrojanClicker:Win32/Toubaom.A!bit” infection

Malware Removal

The TrojanClicker:Win32/Toubaom.A!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanClicker:Win32/Toubaom.A!bit virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

Related domains:

www.baidu.com
passport.baidu.com
q22339398.blog.163.com
ocsp.globalsign.com
crl.globalsign.net
blog.163.com
ocsp2.globalsign.com
crl.globalsign.com

How to determine TrojanClicker:Win32/Toubaom.A!bit?


File Info:

crc32: 72CF624F
md5: 10042ed219c1b8718acf3b737df73d54
name: 10042ED219C1B8718ACF3B737DF73D54.mlw
sha1: 568c76e5b342a14732f9db512734d5c6e03b45a5
sha256: bf6988a0d67e4f4a9b691f6899d957b842bcbfa7fca236eb551a6f99956abbf4
sha512: b1c5a566ef69ca017a60bf9cb4dee84902816d52c31620c5d0299bb29f035227b080c708e4e228d88e374eac0034513283ecc1521fd8346fccd608778d4c17d3
ssdeep: 12288:0pqiC/2OGAtkCP4cejGSOpRKWQ1DBd1vCslySQsUaVauEtLe+PXx2VI:0po/2+ttPJLfpRKWQPvNlJUa/aLfPMVI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: AfhagRyx
FileVersion: 4.5.6.2
FileDescription: AfhagRyx
Translation: 0x0804 0x04b0

TrojanClicker:Win32/Toubaom.A!bit also known as:

MicroWorld-eScanTrojan.GenericKD.45037416
FireEyeGeneric.mg.10042ed219c1b871
Qihoo-360Win32/Trojan.565
McAfeeArtemis!10042ED219C1
CylanceUnsafe
VIPRETrojan.Win32.Clicker!BT
SangforTrojan.Win32.Autoit.NOR
K7AntiVirusTrojan ( 0056e5201 )
BitDefenderTrojan.GenericKD.45037416
K7GWTrojan ( 0056e5201 )
Cybereasonmalicious.219c1b
BaiduWin32.Trojan-Downloader.Autoit.p
CyrenW32/Autoit.F.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Autit.bz
AlibabaTrojanClicker:Win32/Toubaom.6bfbe06b
TencentWin32.Trojan.Autit.Dsyu
Ad-AwareTrojan.GenericKD.45037416
EmsisoftTrojan.GenericKD.45037416 (B)
ComodoMalware@#23bkwwwmg66ds
F-SecureHeuristic.HEUR/AGEN.1105065
ZillyaDownloader.Autoit.Win32.3
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.AutoIt
AviraHEUR/AGEN.1105065
MAXmalware (ai score=89)
MicrosoftTrojanClicker:Win32/Toubaom.A!bit
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D2AF3768
ZoneAlarmTrojan.Win32.Autit.bz
GDataTrojan.GenericKD.45037416
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.Generic.C4268751
ALYacTrojan.GenericKD.45037416
MalwarebytesMalware.AI.4239839747
ESET-NOD32multiple detections
eGambitUnsafe.AI_Score_70%
FortinetMalicious_Behavior.SB
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureWorm.Win32.AutoIt.QN

How to remove TrojanClicker:Win32/Toubaom.A!bit?

TrojanClicker:Win32/Toubaom.A!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment