Trojan

TrojanDropper:Win32/Hokobot.A!dha (file analysis)

Malware Removal

The TrojanDropper:Win32/Hokobot.A!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Hokobot.A!dha virus can do?

  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanDropper:Win32/Hokobot.A!dha?


File Info:

crc32: 53221E34
md5: 826b772c81f41505f96fc18e666b1acd
name: 6674ffe375f8ab54cfa2a276e4a39b414cf327e0b00733c215749e8a94385c63
sha1: 3d1ebf3d6dfaf1d3c047b8e3766ec02a1b95c92d
sha256: 6674ffe375f8ab54cfa2a276e4a39b414cf327e0b00733c215749e8a94385c63
sha512: 1844e731ad9b32aef8c7527b50f9b55585770cb3f7980c50807a1a447d23f197a74e31f7777f1a26a508f9d21fc36182a60b231b36125d65c90e1751a5be2c9f
ssdeep: 12288:21DqIZOJDxV+P9oxGgm9haTCt231b7XZhmwXEvb4PmLGuyHvv:2hq9Eg8STCtE1nphmwzuLGFHX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: rundll32.exe
FileVersion: 2, 0, 0, 2
CompanyName: Microsoft Corporation
SpecialBuild: 2, 0, 0, 2
Comments: Windows Help Service
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 2, 0, 0, 2
FileDescription: Windows Help Service
OriginalFilename: rundll32.exe
Translation: 0x0409 0x04b0

TrojanDropper:Win32/Hokobot.A!dha also known as:

BkavW32.EncapterLTE.Trojan
MicroWorld-eScanGen:Variant.Graftor.188364
FireEyeGeneric.mg.826b772c81f41505
ALYacGen:Variant.Graftor.188364
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agent.tpn8
K7AntiVirusTrojan ( 004bb6551 )
BitDefenderGen:Variant.Graftor.188364
K7GWTrojan ( 004bb6551 )
CrowdStrikewin/malicious_confidence_80% (W)
TrendMicroBKDR_EXPLOSIVE.A
BitDefenderThetaGen:NN.ZexaF.33558.Wq3@aq4PGkdO
F-ProtW32/Explosive.D.gen!Eldorado
SymantecTrojan.Explod
ESET-NOD32Win32/Agent.PTM
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Explosive-6539544-0
GDataGen:Variant.Graftor.188364
KasperskyTrojan.Win32.Agent.adsct
AlibabaTrojanDropper:Win32/Hokobot.3edf1fc8
NANO-AntivirusTrojan.Win32.Agent.ctqhvz
ViRobotTrojan.Win32.Explosive.801467
RisingDropper.Hokobot!8.469E (TFE:5:NiDhZdgYJJI)
Ad-AwareGen:Variant.Graftor.188364
SophosTroj/Explos-E
ComodoMalware@#u2vprdbneotb
F-SecureTrojan.TR/Agent.801467
DrWebTrojan.DownLoader9.11247
ZillyaTrojan.Agent.Win32.441529
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.bm
CMCTrojan.Win32.Agent!O
EmsisoftGen:Variant.Graftor.188364 (B)
IkarusTrojan-Dropper.Agent
CyrenW32/Explosive.D.gen!Eldorado
JiangminTrojan/Agent.ingw
WebrootW32.Trojan.Explod
AviraTR/Agent.801467
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Agent
Endgamemalicious (high confidence)
ArcabitTrojan.Graftor.D2DFCC
AhnLab-V3Trojan/Win32.Agent.C779672
ZoneAlarmTrojan.Win32.Agent.adsct
MicrosoftTrojanDropper:Win32/Hokobot.A!dha
McAfeeGeneric.dgg
VBA32Trojan.Agent
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_EXPLOSIVE.A
YandexTrojan.Agent!XxK1outbKSg
eGambitGeneric.Malware
FortinetW32/Agent.ADSCT!tr
AVGWin32:Explosive-I [Trj]
Cybereasonmalicious.c81f41
AvastWin32:Explosive-I [Trj]
Qihoo-360Win32/Trojan.efc

How to remove TrojanDropper:Win32/Hokobot.A!dha?

TrojanDropper:Win32/Hokobot.A!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment