Trojan

About “Trojan:Win32/BHO” infection

Malware Removal

The Trojan:Win32/BHO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/BHO virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Attempts to create or modify a Browser Helper Object
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.ip138.com
top.ip138.com
2020.ip138.com
hm.baidu.com

How to determine Trojan:Win32/BHO?


File Info:

crc32: 3F236203
md5: f0b5ba617b0e8e332565048129f2a81c
name: ip.exe
sha1: cd0c1bbbae9ca248461143f90b9420ddbd706340
sha256: d6ab83eacbf96d90f3814d95acc8017c2de06d7d970486ba05dbd8fd7873bd4a
sha512: a123a5835d49d1b380073e579816ddd3efb97f22fa258136a57c3397ce1a9f9834c92ad052295c8ef5e174a0bfbb416a1a9fd87b4e243fadb8c8fe44cb49e79d
ssdeep: 6144:Uaw97QQZ35+G5BnOkvBYWODE/84A8W/velM5LTbP85RCezbwm:K97QQZ35/5pBZYWPgZn1A5R/1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
InternalName: ip
FileVersion: 1.05
CompanyName: www.iuuiuu.cn
ProductName: IPx5730x5740x5728x7ebfx67e5x8be2x5668
ProductVersion: 1.05
FileDescription: IPx5730x5740x5728x7ebfx67e5x8be2x5668
OriginalFilename: ip.exe

Trojan:Win32/BHO also known as:

FireEyeGeneric.mg.f0b5ba617b0e8e33
CAT-QuickHealTrojan.BHO
McAfeeGenericRXDN-TD!F0B5BA617B0E
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.BHO.tnIq
K7GWTrojan ( 00500cea1 )
K7AntiVirusTrojan ( 00500cea1 )
TrendMicroTROJ_GEN.F4AEZIL
SymantecTrojan.Gen
TotalDefenseWin32/AdClicker.BCI
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Taob-67
GDataWin32.Trojan.Agent.1RSU5L
KasperskyTrojan.Win32.BHO.cttg
AlibabaTrojan:Win32/BHO.bfd06f15
NANO-AntivirusTrojan.Win32.BHO.dwvebd
RisingDropper.Generic!8.35E (TFE:5:gMrR4YsWYzU)
ComodoMalware@#3qs84e0kauulb
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader9.47888
ZillyaDropper.Taob.Win32.221
Invinceaheuristic
McAfee-GW-EditionGenericRXDN-TD!F0B5BA617B0E
Trapminemalicious.moderate.ml.score
CMCTrojan-Dropper.Win32.Taob!O
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
JiangminTrojan.BHO.c
WebrootW32.SisProc.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=98)
Antiy-AVLTrojan[Dropper]/Win32.Taob
Endgamemalicious (high confidence)
SUPERAntiSpywareTrojan.Agent/Gen-DownLoader
ZoneAlarmTrojan.Win32.BHO.cttg
MicrosoftTrojan:Win32/BHO
AhnLab-V3Dropper/Win32.Taob.C287726
Acronissuspicious
VBA32BScope.Trojan.BHO
CylanceUnsafe
PandaTrj/Genetic.gen
ESET-NOD32Win32/BHO.NZD
TrendMicro-HouseCallTROJ_GEN.F4AEZIL
YandexTrojan.DR.Taob!/OblAUgyQCU
IkarusTrojan-Dropper.Win32.Taob
MaxSecureTrojan.Malware.4944091.susgen
FortinetW32/Generic.AC.1F7017
AVGWin32:Crypt-RUR [Trj]
AvastWin32:Crypt-RUR [Trj]

How to remove Trojan:Win32/BHO?

Trojan:Win32/BHO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment