Trojan

About “Trojan-Banker.Win32.Danabot.eet” infection

Malware Removal

The Trojan-Banker.Win32.Danabot.eet is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Danabot.eet virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Spanish
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Danabot.eet?


File Info:

crc32: 71E23620
md5: 74bb3b9ca0cf6441f94ce2c2d5b3f8fb
name: vps.exe
sha1: 2c1401f6b5c20df4510f3ed55fe94416485fec3e
sha256: ecb84d2791f739ff8ad581fb2e126cf140ee8b9f35b4bf063c99c72d2b608b0e
sha512: a5e979954e161a0fd54f48a170ff9c3cff9dd8467b659f11ffa27de2fdbff590dcdbee78266c432e1dbd9a46f9a60c973f85255236013b6cfef78d12988fcb1c
ssdeep: 12288:VhoKcJZE24rNIgW+tvvV/Puc4SeKswmMv:7oKc3fgW8vvJSSJFmMv
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Danabot.eet also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.42840900
FireEyeGeneric.mg.74bb3b9ca0cf6441
Qihoo-360Win32/Trojan.BO.8da
McAfeeArtemis!74BB3B9CA0CF
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42840900
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_90% (W)
TrendMicroTROJ_GEN.R011C0DCE20
SymantecRansom.Nemty
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.42840900
KasperskyTrojan-Banker.Win32.Danabot.eet
AlibabaTrojanBanker:Win32/Danabot.711ce0be
ViRobotTrojan.Win32.Z.Rypack.593408
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Kryptik!8.8 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42840900 (B)
F-SecureTrojan.TR/Crypt.Agent.ngulv
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.moderate.ml.score
SophosMal/RyPack-A
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.Agent.ngulv
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Generic.D28DB344
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmTrojan-Banker.Win32.Danabot.eet
MicrosoftTrojan:Win32/Azorult.VSD!MTB
AhnLab-V3Trojan/Win32.MalPe.R328530
Acronissuspicious
VBA32BScope.Trojan.AET.281105
ALYacTrojan.GenericKD.42840900
Ad-AwareTrojan.GenericKD.42840900
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBWN
TrendMicro-HouseCallTROJ_GEN.R011C0DCE20
SentinelOneDFI – Malicious PE
FortinetW32/Danabot.A!tr
BitDefenderThetaGen:NN.ZexaF.34100.KuW@aarZRJiG
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.6b5c20
AvastWin32:TrojanX-gen [Trj]
MaxSecureTrojan.Malware.77515321.susgen

How to remove Trojan-Banker.Win32.Danabot.eet?

Trojan-Banker.Win32.Danabot.eet removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment