Trojan

Trojan:Win32/BHO!pz removal guide

Malware Removal

The Trojan:Win32/BHO!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/BHO!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/BHO!pz?


File Info:

name: 7286BA674DA84699C9E0.mlw
path: /opt/CAPEv2/storage/binaries/c246754c479c0f36a559b046c43eb5b4d9f7e04255258b0030baa8a890ce0d59
crc32: BF79CA66
md5: 7286ba674da84699c9e0c996c3ec05ec
sha1: 9b6a7323dc3afec82994ee684fb99c162632a6d2
sha256: c246754c479c0f36a559b046c43eb5b4d9f7e04255258b0030baa8a890ce0d59
sha512: dd71276b478e9d0f5173b4ac459be41d62351bb76dabe706a88a2168e6a8bc657960268afa071950c29c051a96eed21a250f3303b0a2dbb7ad0417c74853c651
ssdeep: 12288:LplrVbDdQaqdS/ofraFErH8uB2Wm0SX/Nr5FU:9xRQ+Fucuvm0a/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F948C02B7A0E170D6C311398F136B7675FAAFA52B61E7C72380FA4D9935AC1A53530B
sha3_384: 50de8c6dce45b8116c956531c37acd24e4fa9224aa3b193cc30e1d7a5f1d9a5b6a6a13bd3fa957986216fb472a8f20c6
ep_bytes: 6a606880554400e8421a0000bf940000
timestamp: 2010-08-26 04:54:16

Version Info:

FileVersion: 1.0.0.21
ProductVersion: 1.0.0.21
Translation: 0x0804 0x03a8

Trojan:Win32/BHO!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Johnnie.4127
FireEyeGeneric.mg.7286ba674da84699
SkyhighBehavesLike.Win32.StartPage.gm
McAfeeGenericRXHE-XQ!7286BA674DA8
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.BHO.Win32.13933
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 001cac2a1 )
K7GWTrojan ( 001cac2a1 )
Cybereasonmalicious.3dc3af
BaiduWin32.Trojan.BHO.n
VirITTrojan.Win32.Agent2.BVKT
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Agent.RXZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Gamup.qko
BitDefenderGen:Variant.Johnnie.4127
NANO-AntivirusTrojan.Win32.Gamup.fnqhik
SUPERAntiSpywareTrojan.Agent/Gen-Fugrafa
AvastWin32:BHO-ACI [Trj]
TencentTrojan-Downloader.Win32.Gamup.fb
SophosTroj/Darbyen-A
F-SecureTrojan.TR/BHO.efkmnb
DrWebTrojan.DownLoad2.34625
VIPREGen:Variant.Johnnie.4127
EmsisoftGen:Variant.Johnnie.4127 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1ICICGF
JiangminTrojan/Generic.bkcdl
GoogleDetected
AviraTR/BHO.efkmnb
MAXmalware (ai score=87)
Antiy-AVLTrojan[Downloader]/Win32.Gamup
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.BHO.EFKMNB@4ok0yf
ArcabitTrojan.Johnnie.D101F
ZoneAlarmTrojan-Downloader.Win32.Gamup.qko
MicrosoftTrojan:Win32/BHO!pz
VaristW32/Trojan.OQDS-0111
AhnLab-V3Win-Trojan/Onlinegamehack21.Gen
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.zu3@aOnXUHob
ALYacGen:Variant.Johnnie.4127
VBA32TrojanDownloader.Gamup
Cylanceunsafe
PandaTrj/Lineage.LOE
ZonerTrojan.Win32.82481
RisingBackdoor.Agent!1.69D8 (CLASSIC)
IkarusTrojan.Spy.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/ZLob.AAAA!tr.dldr
AVGWin32:BHO-ACI [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/BHO!pz?

Trojan:Win32/BHO!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment