Trojan

Win32/TrojanDropper.Binder.NBH removal tips

Malware Removal

The Win32/TrojanDropper.Binder.NBH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Win32/TrojanDropper.Binder.NBH virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/TrojanDropper.Binder.NBH?


File Info:

crc32: 8A939C34
md5: 33545a33dbfe7c0ce7a3bbae159a801e
name: 341107.jpg
sha1: a8e1aafe3c161371b26250c0ae876090f0a4ba82
sha256: 1f036e827ea47e2ca51cea2ba6935c75711c1f048feb5d76a24649a8466a0d86
sha512: 61f35764ea19ace3c0f843b62011f5971867f6e3c66e19970f9548563b40a1c54e68898bc9b6d5b12353ee869ddee20dc0958e43529558e71e631c61093772a4
ssdeep: 24576:hqWn8RZz/gMbER1Nbb4RFeHi7YmJXFsoPvWZ:hiRZDgqER1NARFeHE5Fso3W
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/TrojanDropper.Binder.NBH also known as:

BkavW32.GenericBinderLnr.Trojan
MicroWorld-eScanGen:Variant.Binder.1
CMCHackTool.Win32.Binder!O
CAT-QuickHealVirTool.Vbinder.CO5
McAfeeTrojan-FDDZ!33545A33DBFE
MalwarebytesHackTool.Binder
SUPERAntiSpywareTrojan.Agent/Gen-Binder
K7AntiVirusTrojan ( 004babd11 )
AlibabaHackTool:Win32/Binder.8c5678c5
K7GWTrojan ( 004babd11 )
Cybereasonmalicious.3dbfe7
ArcabitTrojan.Binder.1
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.32250.tvW@auWDC!pG
CyrenW32/Backdoor.FVDJ-1096
SymantecSMG.Heur!gen
TotalDefenseWin32/Tnega.AGBZ
BaiduWin32.Trojan-Dropper.Binder.m
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Trojan.Binder-6
KasperskyHackTool.Win32.Binder.bs
BitDefenderGen:Variant.Binder.1
Paloaltogeneric.ml
AegisLabHacktool.Win32.Binder.lo77
Ad-AwareGen:Variant.Binder.1
EmsisoftGen:Variant.Binder.1 (B)
ComodoTrojWare.Win32.TrojanDropper.Binder.cls@4m6ovz
F-SecureHeuristic.HEUR/AGEN.1026512
DrWebTrojan.MulDrop2.39589
VIPRETrojan-Dropper.Win32.Binder.bs (v)
TrendMicroTROJ_BINDER_FC1700C9.UVPA
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.33545a33dbfe7c0c
SophosMal/Fareit-V
SentinelOneDFI – Malicious PE
F-ProtW32/Backdoor2.HKXU
JiangminHackTool.Binder.bh
AviraHEUR/AGEN.1026512
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftVirTool:Win32/Vbinder.CO
Endgamemalicious (high confidence)
ViRobotTrojan.Win32.A.Swisyn.49120
ZoneAlarmHackTool.Win32.Binder.bs
GDataWin32.Trojan.Binder.A
AhnLab-V3HackTool/Win32.Vbinder.R12127
Acronissuspicious
VBA32Binder.Celesty
ALYacGen:Variant.Binder.1
CylanceUnsafe
ESET-NOD32Win32/TrojanDropper.Binder.NBH
TrendMicro-HouseCallTROJ_BINDER_FC1700C9.UVPA
RisingDropper.Binder!1.AEB1 (CLASSIC)
YandexHackTool.Binder!IMtdREcP3/k
IkarusTrojan.Win32.Dorv
MaxSecureHackTool.W32.Binder.bs
FortinetW32/Dropper.NBH!tr
AVGFileRepMalware
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Hacktool.4af

How to remove Win32/TrojanDropper.Binder.NBH?

Win32/TrojanDropper.Binder.NBH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment