Adware

What is “Win32/Adware.BHO.NLN”?

Malware Removal

The Win32/Adware.BHO.NLN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.BHO.NLN virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Win32/Adware.BHO.NLN?


File Info:

name: 2B67B97727BC619DD816.mlw
path: /opt/CAPEv2/storage/binaries/88f972b03bf5283b3d03cdac0b19834cbd834e75623a1509b822f03cf5ed5f65
crc32: DACC52EC
md5: 2b67b97727bc619dd816f921bdb6b83e
sha1: c9fcad66185840af2ea17e175a3ed909f52beb02
sha256: 88f972b03bf5283b3d03cdac0b19834cbd834e75623a1509b822f03cf5ed5f65
sha512: 2cd6047e317c7a88dbb7701d89e3d33ec2120d5ec798dfaa9ed8f327f03e4385b3657f61dd380c8e36f62be714d8a971f07c124a84f4e3e245a9c2e453fb8313
ssdeep: 12288:PSADDHyj7/BbmaDEPoiAtPA6lHu1PUK1Fp3ScTbNNwmwBJwBarsGSjs:7y9EAZI6lK1FpTTBKmGJGays
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153056B51B481C034F9BD01BC02E99777262B6A225716D6E377AC5D0A3B201FE7EF4A36
sha3_384: e34f949d2325ae87dddd01ff26ea635519c17e07ad4483ec5f2b39dd32d09db8be08b915445c031d47c24dd822493512
ep_bytes: e8a7d10000e9000000006a1468b85348
timestamp: 1970-01-01 04:11:05

Version Info:

FileVersion: 1.5.6.2919
ProductVersion: 15, 6.29
Translation: 0x0804 0x04b0

Win32/Adware.BHO.NLN also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.45515
MicroWorld-eScanGen:Variant.Zusy.306696
FireEyeGeneric.mg.2b67b97727bc619d
CAT-QuickHealTrojan.Skeeyah.17537
ALYacGen:Variant.Zusy.306696
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
K7GWAdware ( 004c75cb1 )
K7AntiVirusAdware ( 004c75cb1 )
BitDefenderThetaGen:NN.ZexaF.34606.Yq0@aqipz7ej
VirITTrojan.Win32.Generic.BWKL
CyrenW32/Horst.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.BHO.NLN
APEXMalicious
ClamAVWin.Malware.Jaik-9660700-0
KasperskyTrojan.Win32.Agent.iguu
BitDefenderGen:Variant.Zusy.306696
NANO-AntivirusTrojan.Win32.Crypted.dtlasb
AvastWin32:GenMaliciousA-QKI [Trj]
TencentMalware.Win32.Gencirc.10b08034
Ad-AwareGen:Variant.Zusy.306696
EmsisoftGen:Variant.Zusy.306696 (B)
ComodoApplication.Win32.AdWare.BHO.AD@5t6i8s
BaiduWin32.Trojan.Agent.aau
ZillyaAdware.BHO.Win32.7751
McAfee-GW-EditionBehavesLike.Win32.Ransomware.ch
SophosAdWin (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Agentb.bpk
WebrootW32.Adware.Gen
AviraTR/Kryptik.qgmpa
Antiy-AVLTrojan/Generic.ASMalwS.1171445
MicrosoftTrojan:Win32/Dorv.A
ArcabitTrojan.Zusy.D4AE08
GDataGen:Variant.Zusy.306696
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.OnLineGames.R156869
McAfeeTrojan-FHGH!2B67B97727BC
MAXmalware (ai score=80)
VBA32BScope.Trojan.KillFiles
MalwarebytesAdware.Graftor
RisingAdWare.Win32.BHO.fkg (RDMK:cmRtazopo1/hO68ndilUn7x4Z4al)
YandexTrojan.GenAsa!ZfO/u3lZgK0
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.IGUU!tr
AVGWin32:GenMaliciousA-QKI [Trj]
PandaTrj/Genetic.gen

How to remove Win32/Adware.BHO.NLN?

Win32/Adware.BHO.NLN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment