Worm

What is “Worm:Win32/Hokobot.A”?

Malware Removal

The Worm:Win32/Hokobot.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Hokobot.A virus can do?

  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Worm:Win32/Hokobot.A?


File Info:

crc32: 790C2EC5
md5: 66e2adf710261e925db588b5fac98ad8
name: e5b68ab68b12c3eaff612ada09eb2d4c403f923cdec8a5c8fe253c6773208baf
sha1: 59796e01dff992fe5ca9cdb54cfb1a23d7a72b77
sha256: e5b68ab68b12c3eaff612ada09eb2d4c403f923cdec8a5c8fe253c6773208baf
sha512: 8034d98962054d32730ce342bc5203fbe0536df19dcd71a63551866122659a8f743cf14d2318988acbf154427475305111b8b0014ca0477b7df45fe2a674fdec
ssdeep: 6144:TS/4o40hfee6uCHCw5+ozQYpNdIDnGGckLThGUuKBu0MpX6S:THop5gCw5+cpNenGx+ThGrKBPMpB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: rundll32.exe
FileVersion: 2, 0, 0, 1
CompanyName: Microsoft Corporation
SpecialBuild: 2, 0, 0, 1
Comments: Windows@ Internet Explorer
ProductName: Windows@ Internet Explorer
ProductVersion: 2, 0, 0, 1
FileDescription: Internet Explorer
OriginalFilename: rundll32.exe
Translation: 0x0409 0x04b0

Worm:Win32/Hokobot.A also known as:

BkavW32.ExplosiveHokobotD.Trojan
DrWebTrojan.DownLoader8.31392
MicroWorld-eScanGen:Variant.Zusy.135070
FireEyeGeneric.mg.66e2adf710261e92
CAT-QuickHealWorm.Hokobot.A5
McAfeeGeneric.dgg
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Explosive.tnnx
SangforMalware
K7AntiVirusTrojan ( 0053af701 )
BitDefenderGen:Variant.Zusy.135070
K7GWTrojan ( 0053af701 )
Cybereasonmalicious.710261
TrendMicroBKDR_EXPLOSIVE.A
BitDefenderThetaGen:NN.ZexaF.32519.xu1@aqn9gaoi
SymantecTrojan.Explod!g2
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Explosive-6538490-0
GDataGen:Variant.Zusy.135070
KasperskyHEUR:Trojan.Win32.Generic
AlibabaWorm:Win32/Hokobot.907b4cf1
NANO-AntivirusTrojan.Win32.Hokobot.dfukpd
ViRobotTrojan.Win32.S.Explosive.377507
RisingWorm.Hokobot!8.5646 (TFE:5:q3okjJYA5bC)
Ad-AwareGen:Variant.Zusy.135070
SophosTroj/Explos-A
ComodoMalware@#39oic1ryrwfhc
F-SecureHeuristic.HEUR/AGEN.1011697
ZillyaTrojan.Agent.Win32.553076
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Suspiciousatg.fh
CMCTrojan.Win32.Explosive!O
EmsisoftGen:Variant.Zusy.135070 (B)
SentinelOneDFI – Malicious PE
JiangminTrojan/Explosive.f
WebrootW32.Explosive
AviraHEUR/AGEN.1011697
Antiy-AVLTrojan/Win32.TSGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Zusy.D20F9E
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Hokobot.A
AhnLab-V3Trojan/Win32.Agent.C779372
Acronissuspicious
VBA32Trojan.Agent
ALYacGen:Variant.Zusy.135070
MAXmalware (ai score=100)
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Agent.PTM
TrendMicro-HouseCallBKDR_EXPLOSIVE.A
YandexTrojan.Explosive!
IkarusTrojan.Win32.Hokobot
FortinetW32/Generic.AC.3f0145
AVGWin32:Explosive-B [Trj]
AvastWin32:Explosive-B [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.382

How to remove Worm:Win32/Hokobot.A?

Worm:Win32/Hokobot.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment