Trojan

Trojan-Banker.Win32.Danabot.ejk removal guide

Malware Removal

The Trojan-Banker.Win32.Danabot.ejk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Danabot.ejk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Unconventionial language used in binary resources: Danish
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.Danabot.ejk?


File Info:

crc32: F68F84D1
md5: c7efb3d126b8628dd7785027a66a74d8
name: vps.exe
sha1: b0145acfa53e5966cbe6850a6061a2e8a4c969b5
sha256: d6b24b283a2ac04f62aaa75d08183e788433add33b0b5f03df9982fb9d401ddb
sha512: e6349f4e40010103f3e90bf060806c03a0948d3860652f8288ed517197bad124ac3bf81fd4c81d725648bde7b5cc23d50e9c105fd5fc1e3f9e61ae76d62a124d
ssdeep: 12288:En9rf3eyVKg/NPHZMe33Y0ZQo81VCTds+G9:wL/jFPHZr3I0ZAC
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Danabot.ejk also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.Siggen9.22707
MicroWorld-eScanTrojan.GenericKD.42860459
FireEyeGeneric.mg.c7efb3d126b8628d
Qihoo-360Win32/Trojan.BO.731
McAfeeArtemis!C7EFB3D126B8
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42860459
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fa53e5
TrendMicroTROJ_GEN.R011C0DCK20
BitDefenderThetaGen:NN.ZexaF.34100.MKW@aqR6yHfG
TrendMicro-HouseCallTROJ_GEN.R011C0DCK20
AvastWin32:TrojanX-gen [Trj]
GDataTrojan.GenericKD.42860459
KasperskyTrojan-Banker.Win32.Danabot.ejk
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/RyPack-A
F-SecureTrojan.TR/Kryptik.tzviv
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.42860459 (B)
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.KPSQ-0504
WebrootW32.Trojan.Gen
AviraTR/Kryptik.tzviv
MAXmalware (ai score=84)
Antiy-AVLTrojan[Banker]/Win32.Danabot
MicrosoftPWS:Win32/Predator.KM!MTB
ArcabitTrojan.Generic.D28DFFAB
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmTrojan-Banker.Win32.Danabot.ejk
AhnLab-V3Trojan/Win32.RL_MalPe.R329194
Acronissuspicious
VBA32BScope.Trojan.AET.281105
ALYacTrojan.GenericKD.42860459
Ad-AwareTrojan.GenericKD.42860459
MalwarebytesSpyware.RaccoonStealer
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HCBL
TencentWin32.Trojan-banker.Danabot.Tbit
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_74%
FortinetPossibleThreat.MU
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Banker.Win32.Danabot.ejk?

Trojan-Banker.Win32.Danabot.ejk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment