Trojan

About “Trojan-Banker.Win32.Danabot.ekv” infection

Malware Removal

The Trojan-Banker.Win32.Danabot.ekv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Danabot.ekv virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Danish
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Danabot.ekv?


File Info:

crc32: 9699B340
md5: 439dca8ddbe6b6cb824897e84bb11783
name: tmp8ofn9swu
sha1: e780f675ef073dcef67fb75e064275ed60d3fac0
sha256: 91e9484bd390393fec30c717aa2c2edf2fe0f8c91469f4e7fae72273b55a2d10
sha512: 773e53929ab34a365db9ad8c03154e95eede50ef72862041f2e826948532dfa172a11b77a69566fcaf78b579165df9810c8933ebdd76b15f549c8dea377579c6
ssdeep: 12288:Jfmyir+p7mMoiGPrLIDzItb2xY0H3k2N:LisGZrLIDzOSxY0H02N
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Danabot.ekv also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.42867210
FireEyeGeneric.mg.439dca8ddbe6b6cb
McAfeeArtemis!439DCA8DDBE6
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0053d5971 )
BitDefenderTrojan.GenericKD.42867210
K7GWTrojan ( 0053d5971 )
APEXMalicious
AvastWin32:DropperX-gen [Drp]
GDataTrojan.GenericKD.42867210
KasperskyTrojan-Banker.Win32.Danabot.ekv
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42867210 (B)
DrWebTrojan.Siggen9.23129
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.high.ml.score
SophosMal/RyPack-A
Antiy-AVLTrojan[Banker]/Win32.Danabot
ArcabitTrojan.Generic.D28E1A0A
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmTrojan-Banker.Win32.Danabot.ekv
MicrosoftPWS:Win32/Predator.KM!MTB
AhnLab-V3Trojan/Win32.MalPe.R329304
Acronissuspicious
VBA32BScope.Trojan.AET.281105
ALYacTrojan.GenericKD.42867210
MAXmalware (ai score=84)
Ad-AwareTrojan.GenericKD.42867210
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HCCS
RisingTrojan.Generic@ML.98 (RDML:iVnkKxXKbnMT2Y8J8qLVcA)
SentinelOneDFI – Suspicious PE
FortinetW32/GenKryptik.EGRK!tr
BitDefenderThetaGen:NN.ZexaF.34100.KuW@aW@rY7dG
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Banker.Win32.Danabot.ekv?

Trojan-Banker.Win32.Danabot.ekv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment