Trojan

How to remove “Trojan:Win32/Bohmini!pz”?

Malware Removal

The Trojan:Win32/Bohmini!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Bohmini!pz virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Bohmini!pz?


File Info:

name: 41FC131203C9D37A3E8E.mlw
path: /opt/CAPEv2/storage/binaries/5dbcdec7cec941b087e5ce40908c494f63bad1d5ed4c60c9bd14f344bf7e500f
crc32: 264B14F0
md5: 41fc131203c9d37a3e8e48d4d57d3471
sha1: c1d6f1cc4272e967e7a15f5fa21c09044311fa6f
sha256: 5dbcdec7cec941b087e5ce40908c494f63bad1d5ed4c60c9bd14f344bf7e500f
sha512: 05ff28391252f04229e5cb9ca9c754f59e3398fdf320abb20d09c01223bd1831cdacc723dce361c23706afe6e6e8e1c5a0c7f2b85cb567fcafe4a179c479f519
ssdeep: 768:n0rhO0/ZQe2bOMvTujmAaA4U8uMua5qOniKZcz:qhOEZQ9OqYVy3p5qmEz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6D2F1A7395C253EF08748FB19E349B098174E44A748641CEFE918E35AD920E3666B7C
sha3_384: 4c727d082f0de72286abee2000039d025df90bbaf5c6f705a49d378e9ae49bbacd9584c6001f4282b993cf4a06c7f7a5
ep_bytes: 518bd15a518bd15a0f315159b9d0ca40
timestamp: 2008-07-14 08:12:54

Version Info:

0: [No Data]

Trojan:Win32/Bohmini!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Firu.kYYd
Elasticmalicious (moderate confidence)
DrWebTrojan.Inject.3608
MicroWorld-eScanTrojan.Downloader.Firu.H
FireEyeGeneric.mg.41fc131203c9d37a
SkyhighBehavesLike.Win32.Generic.mc
McAfeegeneric!bg.ezq
Cylanceunsafe
ZillyaDownloader.Firu.Win32.385
SangforSuspicious.Win32.Save.a
AlibabaTrojanDownloader:Win32/Bohmini.c168ed01
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
ArcabitTrojan.Downloader.Firu.H
BitDefenderThetaAI:Packer.9E422E761F
VirITTrojan.Win32.Agent.BYY
SymantecInfostealer.Gampass
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Firu
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R03FC0CA524
Paloaltogeneric.ml
ClamAVWin.Downloader.52776-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.Firu.H
NANO-AntivirusTrojan.Win32.Firu.msgu
AvastWin32:Bohmini [Cryp]
RisingTrojan.Bohmini!8.924 (TFE:2:b1gBrLYa6HH)
TACHYONTrojan-Downloader/W32.Firu.29824.B
EmsisoftTrojan.Downloader.Firu.H (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
VIPRETrojan.Downloader.Firu.H
TrendMicroTROJ_GEN.R03FC0CA524
Trapminemalicious.high.ml.score
SophosMal/HckPk-A
IkarusGeneric.Trojan-Downloader.JKGD
JiangminTrojanDownloader.Firu.cm
WebrootW32.Trojan.Downloader
GoogleDetected
AviraTR/Crypt.ULPM.Gen
VaristW32/Agent.BP.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Firu
KingsoftWin32.Trojan.Generic.a
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/Bohmini!pz
ViRobotTrojan.Win32.Downloader.29824.EJ
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Downloader.Firu.H
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Firu.C6691
VBA32TrojanDropper.Dinwod
ALYacTrojan.Downloader.Firu.H
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Firu.A
TencentMalware.Win32.Gencirc.10bf7859
YandexTrojan.GenAsa!bFUZVFVhwC4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Firu.KNB!tr.dldr
AVGWin32:Bohmini [Cryp]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Firu.H

How to remove Trojan:Win32/Bohmini!pz?

Trojan:Win32/Bohmini!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment