Malware

How to remove “Troj/Luiha-BN”?

Malware Removal

The Troj/Luiha-BN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Luiha-BN virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Troj/Luiha-BN?


File Info:

name: B3E7E9290E2CC6823D8A.mlw
path: /opt/CAPEv2/storage/binaries/916d8092b3f45a2e88cf86f812251e59eaca463ad0718827d91849b1ab35c0fe
crc32: 54E1A343
md5: b3e7e9290e2cc6823d8ae6835c0041c2
sha1: fbff3177fc2e8aa85cc33f9d9bbed2af427c274a
sha256: 916d8092b3f45a2e88cf86f812251e59eaca463ad0718827d91849b1ab35c0fe
sha512: 71e20bb43dd668707253acb9b5e055f8a6d6796283124991f0d1e18201ade72fe89556b4511cc81cb60ce991bdf174dde27ea5e608ecbe5c266774f9fe876d5a
ssdeep: 6144:Xuq1yy/pjnkWcLkONgMDGMHTiLCwKurwNKZkpeY:v1yc9kWc4u7DGMyC7peY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T128440196B8D1D079C0504DF49C3582843677BA702F3D54A7BFAA5FCDECB92C26A0D886
sha3_384: 0a746e16b48b4d680e33f7998b2a8158141d99d041fffc7890da1f04715c6ef7cc7f126c069830e0a729970f36864906
ep_bytes: 558becb9060000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Troj/Luiha-BN also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Delf.lyLM
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.74193
FireEyeTrojan.GenericKDZ.74193
McAfeeExploit-Mydoom
Cylanceunsafe
ZillyaBackdoor.Delf.Win32.19910
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaBackdoor:Win32/Dorv.5eeed48a
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.7fc2e8
CyrenW32/Delfloader.B.gen!Eldorado
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Delf-6717516-0
KasperskyBackdoor.Win32.Delf.ars
BitDefenderTrojan.GenericKDZ.74193
SUPERAntiSpywareTrojan.Agent/Gen-Delf
TencentTrojan.Win32.IRCbot.nrc
SophosTroj/Luiha-BN
BaiduWin32.Trojan.Delf.j
DrWebBackDoor.IRC.Sdbot.16412
VIPRETrojan.GenericKDZ.74193
TrendMicroBackdoor.Win32.MYDOOM.SMJT
McAfee-GW-EditionBehavesLike.Win32.ExploitMydoom.dc
EmsisoftTrojan.GenericKDZ.74193 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Worm.MyDoom.B
JiangminBackdoor/Delf.hxo
MAXmalware (ai score=88)
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumBackdoor.Win32.Agent.~AACE@2m6u4
ArcabitTrojan.Generic.D121D1
ZoneAlarmBackdoor.Win32.Delf.ars
MicrosoftTrojan:Win32/CoinMiner!pz
GoogleDetected
AhnLab-V3Backdoor/Win32.Delf.R238368
Acronissuspicious
ALYacTrojan.GenericKDZ.74193
TACHYONBackdoor/W32.DP-Delf.Zen
MalwarebytesGeneric.Backdoor.IRCBot.DDS
PandaBck/Delf.AAQ
TrendMicro-HouseCallBackdoor.Win32.MYDOOM.SMJT
RisingBackdoor.Delf!1.64C1 (CLASSIC)
IkarusTrojan.Win32.IRCBot
MaxSecureTrojan.W32.Delf.Ars
FortinetW32/MyDoom.SMM!tr.bdr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Luiha-BN?

Troj/Luiha-BN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment