Trojan

Trojan-Banker.Win32.Danabot.hgz removal tips

Malware Removal

The Trojan-Banker.Win32.Danabot.hgz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Danabot.hgz virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Danish
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r4—sn-4g5e6ns6.gvt1.com

How to determine Trojan-Banker.Win32.Danabot.hgz?


File Info:

crc32: 5C0DE00F
md5: c0b5867b703dd4bb9e22ea74716692b4
name: tmphkca03x8
sha1: 12bf93544aa8442b20d0d77267b2c44d6fad780f
sha256: a7f36b933661e2d1d30d738fc6eba1f94b710daa354476c406cecfdb93d63085
sha512: f019227efc9121297f5a927a0ec6bf125e0f2bcd5fd25eac83f64c13c079d5da5016af8781cea407c4fffd1114b85bee1dc80026646781e41644ca67a3adc753
ssdeep: 49152:Agvvl6qsKZI7HgqWW4xClZXO/mBV8XfFtpEmf1x3jU40Qd3QsXSZm+8H9HcukOy:AgvvrZ0HEbeuXfN1xgqd3QsXSZmjH9H
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Danabot.hgz also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKDZ.67892
FireEyeGeneric.mg.c0b5867b703dd4bb
Qihoo-360HEUR/QVM10.1.ED1F.Malware.Gen
McAfeeGenericRXAA-AA!C0B5867B703D
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005686901 )
BitDefenderTrojan.GenericKDZ.67892
K7GWTrojan ( 005686901 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan-Banker.Win32.Danabot.hgz
RisingMalware.Obscure/Heur!1.9E03 (RDMK:cmRtazquN0/+GzzE9dyZ01tCPdMQ)
Ad-AwareTrojan.GenericKDZ.67892
EmsisoftTrojan.GenericKDZ.67892 (B)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
FortinetW32/GenKryptik.EMLL!tr
Antiy-AVLTrojan/Win32.Injuke
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D10934
ZoneAlarmTrojan-Banker.Win32.Danabot.hgz
MicrosoftTrojan:Win32/Danabot.VC!MTB
AhnLab-V3Trojan/Win32.MalPe.R340422
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34128.OAW@a4D55DaG
ALYacTrojan.GenericKDZ.67892
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HEBH
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
GDataTrojan.GenericKDZ.67892
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Banker.Win32.Danabot.hgz?

Trojan-Banker.Win32.Danabot.hgz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment