Home Malware Programs Trojans Bohu Trojan

Bohu Trojan

Posted: June 29, 2011

Bohu Trojan may refer to one of several different Trojans – some versions of which attack your network settings to restrict security information, others will prevent security-related processes from running, while yet another type of Bohu Trojan infection will redirect your web browser to malicious websites. Many of these Bohu Trojan infections will cooperate with each other and can be found as symptoms of a large multi-Trojan attack. Other types of Bohu Trojan may work independently. No matter which type of Bohu Trojan you have on your PC, Bohu Trojan is a dangerous security risk that requires the use of advanced security software to delete Bohu Trojan components from your computer.

The Insidious Preemptive Defense Tactic of Certain Bohu Trojans

Different types of Bohu Trojan infections have been seen in 2010, but many updates have occurred as late as June 2011. Keep your security software updated to prevent Bohu Trojan from wreaking havoc without being detected.

Two of the primary types of Bohu Trojan infections include TrojanDropper:Win32/Bohu.A and Trojan:Win32/Bohu.A!Installer. TrojanDropper:Win32/Bohu.A exists simply to install Trojan:Win32/Bohu.A!Installer and will do so by pretending to be a fake codec or other movie player update. Trojan:Win32/Bohu.A!Installer then uses custom drivers and Windows Sockets SPIs to restrict the infected computer's network traffic with the explicit intent of preventing your PC from transmitting malware-related information to security companies.

This attack can hinder your ability to perform any action that requires you to upload information to a server and may make it more difficult to defeat both types of Bohu Trojan attackers. As if all that wasn't enough, the second variety of Bohu Trojan infections has also been seen adding randomized information to files to prevent security programs from detecting the Bohu Trojan code.

At the Other End of Bohu Trojan – Rootkits and Hijackers

Bohu Trojan can also take a number of other major forms:

  • Bohu Trojan may be a rootkit and a harmful kernel-mode driver. Rootkits are extremely difficult to detect or remove without advanced assistance from anti-malware applications. The rootkit form of Bohu Trojan has been seen being installed by yet another Bohu Trojan: TrojanDropper:Win32/Bohu.B. The primary goal of this rootkit-based Bohu Trojan is to stop processes related to Chinese anti-virus software.
  • Some variants of Bohu Trojan are also browser hijackers. These hijackers redirect you away from certain Chinese websites like taobao.com and baidu.com and towards unrelated and possibly malicious sites. Browser hijackers may also create pop-ups, change your homepage settings or display fake error messages that constrict your website access

All types of Bohu Trojan infections should be considered high-level threats to your security, even if you don't see visible signs of their attacks, files or active memory processes. You can delete Bohu Trojan infections by using advanced and updated anti-virus software.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%baidu msfsg.exe
    2 %ProgramFiles%baidu s0001.xml
    3 %ProgramFiles%baidu t0001.xml
    4 %ProgramFiles%baidudsop7.xml
    5 %System%\nethome32.dll
    6 %System%\netplayone\MyIEData\main.ini
    7 %System%\netplayone\MyIEData\SysDat.bin
    8 %System%\netplayone\netplayone.dll
    9 %System%\passthru.dll
    10 %System%\siglow.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetHomeIDEHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PassthruHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\"PackedCatalogItem" = "%System%\netplayone\netplayone.dll"Read more how to delete Trojan.Bohu registry entriesHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\speednet_sph\"PathName" = "%System%\netplayone\netplayone.dll"
Loading...