Trojan

Trojan-Banker.Win32.Danabot.egd removal guide

Malware Removal

The Trojan-Banker.Win32.Danabot.egd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Danabot.egd virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (5 unique times)
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Danabot.egd?


File Info:

crc32: F98565C0
md5: 5dad17c043750c9293032d2a28750e2e
name: vps.exe
sha1: 4241ce88185b360ce9a0a8d5b8a8ccd72907dc66
sha256: e8eb82ee9c7935cfd772b85bb10ac48c0e424e53ae37f7dc12fbdc2369ccae6d
sha512: 133c168ebe9d5aa2da892d7081dbfbc1cc140ad786121d80c460370171ce443ded54c60f9dbf162d1d91baef043afbc49d92f7562b6726b6c247c13da90fe6ce
ssdeep: 12288:ZMTuiFaOA77mp2TiDOo/PFQ1Fc5XhM0XzsGi+T4iUovwxxb:ZEuisvOPKOP21Fi5DsGi+MXoozb
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Danabot.egd also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33543905
Qihoo-360Win32/Trojan.BO.f56
McAfeeArtemis!5DAD17C04375
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33543905
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_GEN.R011C0DCG20
BitDefenderThetaGen:NN.ZexaF.34100.KOW@aqQG8Hr
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.33543905
KasperskyTrojan-Banker.Win32.Danabot.egd
TencentWin32.Trojan-banker.Danabot.Szmb
Ad-AwareTrojan.GenericKD.33543905
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.cxlml
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.5dad17c043750c92
EmsisoftTrojan.GenericKD.33543905 (B)
IkarusTrojan.Win32.Krypt
AviraTR/Crypt.Agent.cxlml
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FFD6E1
ZoneAlarmTrojan-Banker.Win32.Danabot.egd
MicrosoftTrojan:Win32/Danabot.DSK!MTB
AhnLab-V3Trojan/Win32.MalPe.R328801
Acronissuspicious
ALYacTrojan.Trickster.Gen
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBYA
TrendMicro-HouseCallTROJ_GEN.R011C0DCG20
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
YandexTrojan.Kryptik!O/D2mCzpoi0
SentinelOneDFI – Malicious PE
FortinetW32/GenKryptik.EGGS!tr
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.8185b3
AvastWin32:CoinminerX-gen [Trj]

How to remove Trojan-Banker.Win32.Danabot.egd?

Trojan-Banker.Win32.Danabot.egd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment