Malware

Win32/BlackHole removal

Malware Removal

The Win32/BlackHole is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/BlackHole virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with NsPack
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/BlackHole?


File Info:

name: C36E81AB066D57F2B0D8.mlw
path: /opt/CAPEv2/storage/binaries/e099013d70196c13badcd3a7fc2b08216daa345cc1b68868e00d2fd23020475a
crc32: 2A073224
md5: c36e81ab066d57f2b0d8c43e920a4cd7
sha1: edab14c071d49d035a4ac1e04b2b85b17fa5b408
sha256: e099013d70196c13badcd3a7fc2b08216daa345cc1b68868e00d2fd23020475a
sha512: fe6db8e30e960fad48ead206ec9cc45f45d95acfdf1606c721342070ec495ad3bbaa9542eaf16921e7fb5eb41a86ab98be2762790a5850d33cf78fcf0cbbeddd
ssdeep: 3072:64sZ+i7ryg5fl23SPANkJoT8gw01aLkZaG7Lab/10KWYJcTO+WU8JzCCBm4:64jirywflXPtJuuLECfJcTEzU4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C2412278D5D94ADC4C6E5F6310F405533F0DC29E9CE6C6AA9A23089BCB4BBD9433A1D
sha3_384: 711b7b2edd8d07bc551af9ccdec626ebe52951931ac6c7dd821511d33122341d6e0fc37e25e09943857c51780d985b6a
ep_bytes: f8eb02f8e160730530c5b60139e80700
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/BlackHole also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.BlackHole.2484
MicroWorld-eScanPacker.Expressor.B
FireEyeGeneric.mg.c36e81ab066d57f2
McAfeeGeneric Malware.em
CylanceUnsafe
ZillyaTrojan.BlackHole.Win32.315
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005257651 )
AlibabaBackdoor:Win32/Klone.d0f5cfca
K7GWTrojan ( 005257651 )
Cybereasonmalicious.b066d5
BitDefenderThetaAI:Packer.DD205C121D
VirITBackdoor.Win32.BlackHole.DRO
CyrenW32/Threat-IKNP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/BlackHole
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Hupigon-9763830-0
KasperskyPacked.Win32.Klone.af
BitDefenderPacker.Expressor.B
NANO-AntivirusVirus.Win32.Agent.dvixmz
AvastWin32:Virtualizer [Cryp]
TencentWin32.Packed.Klone.Swuo
SophosML/PE-A + W32/Pidgeon-A
ComodoTrojWare.Win32.Trojan.NSPM.~gen@20n73t
F-SecureBackdoor.BDS/Hupigon.Gen
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.HLLP.dc
EmsisoftPacker.Expressor.B (B)
IkarusBackdoor.Win32.Ceckno
JiangminPacked.Klone.jci
WebrootW32.Backdoor.Gen
AviraBDS/Hupigon.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Packed]/Win32.Klone
MicrosoftBackdoor:Win32/Blackhole.Z
ZoneAlarmPacked.Win32.Klone.af
GDataPacker.Expressor.B
CynetMalicious (score: 100)
VBA32BScope.Trojan.Dynamer
ALYacPacker.Expressor.B
MalwarebytesTrojan.MalPack.NSPack
ZonerProbably Heur.ExeHeaderP
RisingTrojan.Win32.Generic.1458AB3C (C64:YzY0Om+9jLgXYWpy)
YandexTrojan.GenAsa!ZCumm/B2e3w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.14529.susgen
FortinetW32/CoinMiner.BELF!tr
AVGWin32:Virtualizer [Cryp]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32/BlackHole?

Win32/BlackHole removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment