Trojan

TrojanDownloader:Win32/Wintrim.BH malicious file

Malware Removal

The TrojanDownloader:Win32/Wintrim.BH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Wintrim.BH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Wintrim.BH?


File Info:

name: 7947225DA418F0AAA6F1.mlw
path: /opt/CAPEv2/storage/binaries/0dab63b38690bd259587ec78ceb46ea23ea3ba4a7c1465a4b768015a9dc9fa5c
crc32: 0C90B25E
md5: 7947225da418f0aaa6f1b4e4c0a5d84c
sha1: b4d01ff0e7d1544c69b0214837d79d1a7d20f848
sha256: 0dab63b38690bd259587ec78ceb46ea23ea3ba4a7c1465a4b768015a9dc9fa5c
sha512: aaf664344a0b8c9d2ac1d022ac028bbb76cba7662b431a93ca66ece5c41d0fb0188cb2de6bc37892b612a7d4d626a054c64bfb218978bf12d5b566cec52bf9e0
ssdeep: 12288:AMyP/uAeLSp2C/s8OMcfrJFjfGpBejZsQF:Ly+A0C/KMItFDGpBejZsQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14494228BE5EC4019FFF35F34557445ACA4B1398B4AA6C4E826C0C42DE9F5BA0CD94B3A
sha3_384: 0573737eda623b7b195932db461702968c73e5b0451cd557d64f29277e6118766920c885d478abed1274bd0ed7b5ccae
ep_bytes: 558bec6aff68a822450068d01e400064
timestamp: 2006-07-06 20:08:25

Version Info:

CompanyName: hiladizo
FileDescription: eslaboné
FileVersion: 7, 2, 6, 6
InternalName: rosigar
LegalCopyright: estribor
LegalTrademarks: snowdrop
ProductName: s'indemnisèrent
ProductVersion: 7, 2, 6, 6
Translation: 0x0409 0x04b0

TrojanDownloader:Win32/Wintrim.BH also known as:

LionicHacktool.Win32.Hrup.x!c
DrWebTrojan.MulDrop4.55156
MicroWorld-eScanGen:Variant.Adware.NaviPromo.2
SkyhighSkintrim.gen.c
McAfeeSkintrim.gen.c
MalwarebytesMalware.Heuristic.2090
VIPREGen:Variant.Adware.NaviPromo.2
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 700000041 )
AlibabaPacked:Win32/Skintrim.e9ec8072
K7GWTrojan ( 700000041 )
BitDefenderThetaAI:Packer.32FDBC881F
VirITFraudTool.WinRecovery.D
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Skintrim.GH
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R03BC0OAU24
ClamAVWin.Trojan.Agent-280486
KasperskyPacked.Win32.Hrup.b
BitDefenderGen:Variant.Adware.NaviPromo.2
NANO-AntivirusTrojan.Win32.Hrup.ccrca
AvastWin32:Skintrim-2
TencentWin32.Packed.Hrup.Cdhl
EmsisoftGen:Variant.Adware.NaviPromo.2 (B)
F-SecureAdware.ADWARE/Adware.Gen2
ZillyaTrojan.Skintrim.Win32.1040
TrendMicroTROJ_GEN.R03BC0OAU24
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.7947225da418f0aa
SophosMal/SkimTrim-E
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=99)
JiangminPacked.Hrup.abmb
WebrootW32.Orsam.Gen
GoogleDetected
AviraADWARE/Adware.Gen2
VaristW32/Skintrim.B!Generic
Antiy-AVLTrojan[Packed]/Win32.Hrup
KingsoftWin32.Troj.Undef.a
MicrosoftTrojanDownloader:Win32/Wintrim.BH
XcitiumTrojWare.Win32.Trojan.hrup.~GEN@1pv2gt
ArcabitTrojan.Adware.NaviPromo.2
ZoneAlarmPacked.Win32.Hrup.b
GDataGen:Variant.Adware.NaviPromo.2
CynetMalicious (score: 99)
VBA32BScope.Trojan.Wintrim
ALYacGen:Variant.Adware.NaviPromo.2
TACHYONTrojan/W32.Hrup.426496.B
Cylanceunsafe
PandaTrj/CI.A
RisingTrojan.Generic@AI.100 (RDML:zXxShEcevTbz1Hvi08IExQ)
YandexTrojan.Skintrim!uZZX1NC3UAk
IkarusPacker.Win32.Hrup
MaxSecureTrojan.Malware.1237845.susgen
AVGWin32:Skintrim-2
DeepInstinctMALICIOUS
alibabacloudAdWare:Win/Skintrim.GH

How to remove TrojanDownloader:Win32/Wintrim.BH?

TrojanDownloader:Win32/Wintrim.BH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment