Home Malware Programs Trojans TrojanSpy:Win32/Bhoban.E

TrojanSpy:Win32/Bhoban.E

Posted: January 24, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 3
First Seen: January 24, 2013
Last Seen: September 15, 2018
OS(es) Affected: Windows

TrojanSpy:Win32/Bhoban.E is a Trojan that is used to create malicious Browser Helper Objects (BHOs) on the infected computer system. TrojanSpy:Win32/Bhoban.E may be downloaded and executed by other PC threats. When executed, TrojanSpy:Win32/Bhoban.E installs the target BHO in Internet Explorer by adding an entry under the registry key. TrojanSpy:Win32/Bhoban.E also changes the affected computer's setting to always enable BHOs, even if they have previously been disabled or turned off. TrojanSpy:Win32/Bhoban.E does this by hooking the RegOpenKeyExW Windows API to continually register BHO components.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



226d9d7fe3f39d16c08eaf58b3fb096d File name: 226d9d7fe3f39d16c08eaf58b3fb096d
Size: 7.1 KB (7104 bytes)
MD5: 226d9d7fe3f39d16c08eaf58b3fb096d
Detection count: 87
Group: Malware file
Last Updated: January 28, 2013
BAcroIEHelpe228.dll File name: BAcroIEHelpe228.dll
Size: 7.72 KB (7720 bytes)
MD5: 67ee3591949ca8294a40fe624c0209bf
Detection count: 84
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: January 28, 2013
BAcroIEHelpe.dll File name: BAcroIEHelpe.dll
Size: 7.1 KB (7104 bytes)
MD5: 00109fcdb39daec4326d02ba2733f117
Detection count: 83
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: January 28, 2013
BAcroIEHelpe182.dll File name: BAcroIEHelpe182.dll
Size: 6.4 KB (6400 bytes)
MD5: 35ed37c9a3d4336cdc4adf0def7cb579
Detection count: 78
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: January 28, 2013
BAcroIEHelpe205.dll File name: BAcroIEHelpe205.dll
Size: 7.42 KB (7424 bytes)
MD5: 66397632e3f868bcd90b5f3f9f8538c6
Detection count: 76
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: January 28, 2013

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Loading...