Malware

Downloader.Banload.9985 (file analysis)

Malware Removal

The Downloader.Banload.9985 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Banload.9985 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family

How to determine Downloader.Banload.9985?


File Info:

name: D9F754940C260A39C88F.mlw
path: /opt/CAPEv2/storage/binaries/3798374a5236f8a7488164ce64badd095467688a26b28d3f3fe3f5e6f403a7b4
crc32: 3036D736
md5: d9f754940c260a39c88f4a1de8e38053
sha1: a49de41457c154fd648179b0ebf11bc845adb826
sha256: 3798374a5236f8a7488164ce64badd095467688a26b28d3f3fe3f5e6f403a7b4
sha512: 7237c2a02004683a9ce120f5c5d23d0ad09b1cf8bebef2c86c49dd7d51617a178115d8c47fb220b47f2654dff7ecd69fc0d54931d023417f2bc2aa74134cb3f5
ssdeep: 3072:fdpzIp3gvShWom4+yUw0A849nlObSOmcb5QUOPV2I73GMKpDPqgYlFigWPhbuUC:fdpzl6somSUw0p49nT2I73zyPSqgwiUC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T156847DD8768460DACB4ED37351D1C99F233208FE6423984E0596F7DE1E6BB5B4A2CC91
sha3_384: 22b3d3de59f6d97288a342ba47e3634aa1693f15bab65d218976ef3caa9b1db2160e6c4ec0e2fd5de723c497ca987a75
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Downloader.Banload.9985 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CAT-QuickHealDownloader.Banload.9985
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FPON!D9F754940C26
Cylanceunsafe
ZillyaDownloader.Banload.Win32.75725
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Banload.2f8e64b9
Cybereasonmalicious.457c15
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
TencentTrojan-Downloader.Win32.Banload.haq
BaiduWin32.Trojan.Delf.fw
DrWebWin32.HLLW.Siggen.1499
SophosMal/Generic-S
IkarusTrojan.Crypt
JiangminTrojanDownloader.Banload.bovd
VaristW32/S-7050048b!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Banload.baeh
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Downloader/Win32.Banload.C1859984
Acronissuspicious
MalwarebytesGeneric.Malware.AI.DDS
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Downloader.Banload.9985?

Downloader.Banload.9985 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment