Trojan

Trojan:Win32/Conhook.D removal guide

Malware Removal

The Trojan:Win32/Conhook.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Conhook.D virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Conhook.D?


File Info:

name: DF711A1A7EDC568B62D2.mlw
path: /opt/CAPEv2/storage/binaries/56674450277a7888169e1850279fbdb8128b1df0e16d6bf5d4864fe0bd8b6305
crc32: E8381534
md5: df711a1a7edc568b62d26cf9e6d177c3
sha1: 72db706639ce852ab23e0645b3cb9cf3848dd65f
sha256: 56674450277a7888169e1850279fbdb8128b1df0e16d6bf5d4864fe0bd8b6305
sha512: cddb62bdbd92e2df83693dfad0d1c4cabd9fd126d6aab8a83f890fd0f9ef69e4da7d1eb245a14ae0d125d01a9df2dccb0f51566ac2ff39b9400d0001bb7a3cb5
ssdeep: 1536:JrVF+1E6gAtI0mK6SftkIzluaBKM2slK7na+Cq3a6zizKGxrSjeXOYrPqOnBrnGi:JrV8O6ptgeSclucH2vLa+CWTzizKYSjQ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T15B9312BBEB9BAE36CEB820FC0CC9913E7674163459EBAA7C604453314185932478F5F2
sha3_384: bd227169cbe3f11ae8b10026a1a0b4ab57945a26e0c32a0f11b66399553d85bc6a145471beae14cd5d26422661ffb1d2
ep_bytes: 807c2408010f85960b000060be00c001
timestamp: 2008-03-26 07:07:37

Version Info:

0: [No Data]

Trojan:Win32/Conhook.D also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vundo.4!c
DrWebTrojan.Packed.213
MicroWorld-eScanMemScan:Trojan.Vundo.FGM
FireEyeGeneric.mg.df711a1a7edc568b
SkyhighBehavesLike.Win32.Generic.nc
ALYacMemScan:Trojan.Vundo.FGM
Cylanceunsafe
ZillyaTrojan.Monder.Win32.7965
SangforTrojan.Win32.Vundo.V9ym
AlibabaTrojan:Win32/Monder.3f0d5e8e
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZedlaF.36802.fmOfaq7GfMn
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.SuperJuan.A
APEXMalicious
TrendMicro-HouseCallTROJ_VUNDO.SMIB
KasperskyTrojan.Win32.Monder.gen
BitDefenderMemScan:Trojan.Vundo.FGM
NANO-AntivirusTrojan.Win32.Monder.kjclwh
AvastWin32:Vundo@dll [Trj]
EmsisoftMemScan:Trojan.Vundo.FGM (B)
GoogleDetected
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREMemScan:Trojan.Vundo.FGM
TrendMicroTROJ_GEN.R03BC0DBE24
Trapminemalicious.moderate.ml.score
SophosTroj/Virtum-Gen
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Monder.Gen.a
VaristW32/Virtumonde.AX.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Monder
KingsoftWin32.HeurC.KVMH008.a
MicrosoftTrojan:Win32/Conhook.D
XcitiumTrojWare.Win32.Monder.gen@1gs5jk
ArcabitTrojan.Vundo.FGM
ViRobotTrojan.Win.Z.Monder.96256
ZoneAlarmTrojan.Win32.Monder.gen
GDataMemScan:Trojan.Vundo.FGM
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Katusha.R1902
McAfeeArtemis!DF711A1A7EDC
VBA32Trojan.Virtumonde
PandaTrj/CI.A
RisingTrojan.Toga!8.136D (TFE:5:Jgc8gxjYe6T)
YandexTrojan.GenAsa!n1eFp4OeQdE
IkarusTrojan.Win32.DNSChanger
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Monder.BGF!tr
AVGWin32:Vundo@dll [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Conhook.D?

Trojan:Win32/Conhook.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment