Threat Database Trojans Win32.BHO.hxm

Win32.BHO.hxm

By ZulaZuza in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 20
First Seen: December 12, 2011
Last Seen: February 8, 2023
OS(es) Affected: Windows

Win32.BHO.hxm is a dangerous malware infection that criminals use to spy on their victims' online activity and steal online passwords, credit card information and other kinds of sensitive information. The letters BHO in Win32.BHO.hxm stand for Browser Helper Object, a kind of Internet Explorer exploit that many malware infections use to infiltrate the victim's computer system. Win32.BHO.hxm seldom attacks by itself. Most of the time, Win32.BHO.hxm will be downloaded along with a bundle of other malware threats. Without coordinating their attacks, a group of malware including Win32.BHO.hxm can quickly overwhelm a computer system and make their home in your hard drive. ESG security researchers consider that Win32.BHO.hxm poses a significant threat to your privacy and to your computer system's safety. Any instances of Win32.BHO.hxm and its associated malware should be removed immediately with a reliable, fully-updated anti-malware application. Because Win32.BHO.hxm is often associated with malware and the capacity to disable your security software, ESG security researchers strongly recommend that you start up Windows in Safe Mode before attempting to remove Win32.BHO.hxm.
 

Protecting Yourself from Win32.BHO.hxm

There are two main steps that you must take in order to protect yourself from Win32.BHO.hxm and similar malware. First of all, it is necessary to make sure that you install a reliable security program on your computer system and that this program is kept fully updated. Security applications should include an anti-virus program, a firewall, an anti-malware scanner and a spam filter for your email application at the very least. However, this is only the first step in keeping your computer system protected. In fact, most malware will attempt to bypass a security application not by attacking it, but by taking advantage of human nature and the gullibility of inexperienced computer users. This is why the second step in protecting yourself from Win32.BHO.hxm is to make sure that you follow safe browsing practices. Some guidelines to ensure that you do not become infected with malware include never opening attachments contained in unsolicited emails, never clicking on unknown links and never downloading software without first making sure that the source is legitimate and reliable. It is also extremely important to stay away from websites that are generally considered unsafe, such as websites containing pirated software or pornographic videos.

File System Details

Win32.BHO.hxm may create the following file(s):
# File Name Detections
1. %AppData%\RANDOM CHARACTERS

Registry Details

Win32.BHO.hxm may create the following registry entry or registry entries:
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}](Default) = "Browser Helper Object" AppID = "{A0E1054B-01EE-4D57-A059-4D99F339709F}"
(Default) = "0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\main.BHO] (Default) = "Browser Helper Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\main.BHO\CLSID] (Default) = "{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\HELPDIR] (Default) = "%System%\"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\main.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\main.BHO.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\0\win32
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A0E1054B-01EE-4D57-A059-4D99F339709F}] (Default) = "Browser Helper Object" (Default) = "main.BHO"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\ProgID] (Default) = "main.BHO.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\FLAGS]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\main.BHO\CurVer] (Default) = "main.BHO.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\main.BHO.1] (Default) = "Browser Helper Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}] (Default) = "IBHO"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\main.BHO\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\0
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\main.DLL] AppID = "{A0E1054B-01EE-4D57-A059-4D99F339709F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\TypeLib] (Default) = "{8E3C68CD-F500-4A2A-8CB9- 132BB38C3573}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}\TypeLib] (Default) = "{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}" Version = "1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0] (Default) = "main 1.0 Type Library"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\main.BHO.1\CLSID] (Default) = "{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}\ProxyStubClsid]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}] (Default) = "" NoExplorer = 0×00000001
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A0E1054B-01EE-4D57-A059-4D99F339709F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\main.BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\main.BHO.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}

Trending

Most Viewed

Loading...