Trojan

Trojan-Banker.Win32.Danabot.egf removal instruction

Malware Removal

The Trojan-Banker.Win32.Danabot.egf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Danabot.egf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (5 unique times)
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Danabot.egf?


File Info:

crc32: 24C50450
md5: 8ea8f7b15799572def48e54c77d9b3dd
name: vps.exe
sha1: 5a315541d59723e2b45e7253317d3bb82e6e53e0
sha256: 2c7e277182fd8d1c9a8a57acda33158c75324358b2fa1c9c7bff9af6ad1d6d54
sha512: 4df8ebfcb570b40b1080e636dab75f84a72604feda91c232a9561a7ad3795117a35a275ecee14f12e56a1fb2cf9d782bcfc5b5798813ab1a05cd31e564b6e98b
ssdeep: 12288:ZIEcskY/4Wr0lB5Uew1D8/1LJ23lRdQfj1bLcz9k:ZHcskY/FrJn1A/1QlRIFYz
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Danabot.egf also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33544097
FireEyeGeneric.mg.8ea8f7b15799572d
Qihoo-360Win32/Trojan.BO.cd8
McAfeeArtemis!8EA8F7B15799
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33544097
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1d5972
TrendMicroTROJ_GEN.R011C0DCG20
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
GDataTrojan.GenericKD.33544097
KasperskyTrojan-Banker.Win32.Danabot.egf
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan-banker.Danabot.Eero
Ad-AwareTrojan.GenericKD.33544097
EmsisoftTrojan.GenericKD.33544097 (B)
F-SecureTrojan.TR/Crypt.Agent.qlcee
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
AviraTR/Crypt.Agent.qlcee
Antiy-AVLTrojan[Banker]/Win32.Danabot
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FFD7A1
ZoneAlarmTrojan-Banker.Win32.Danabot.egf
MicrosoftTrojan:Win32/Danabot.DSK!MTB
AhnLab-V3Trojan/Win32.MalPe.R328801
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34100.KOW@a88u8Kt
ALYacTrojan.GenericKD.33544097
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBYA
TrendMicro-HouseCallTROJ_GEN.R011C0DCG20
RisingTrojan.Kryptik!1.C3F2 (CLASSIC)
YandexTrojan.Kryptik!Vo7wLP+7wd8
IkarusTrojan.Win32.Crypt
FortinetPossibleThreat.MU
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Banker.Win32.Danabot.egf?

Trojan-Banker.Win32.Danabot.egf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment