Trojan

Trojan.Banload.Agent malicious file

Malware Removal

The Trojan.Banload.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Banload.Agent virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Network activity detected but not expressed in API logs
  • Attempts to disable Windows Defender

How to determine Trojan.Banload.Agent?


File Info:

crc32: C8C0A4DD
md5: 15dd924cfd3eeb96d299c64af87ef732
name: az2.exe
sha1: b4fd61242afbd93bf70bd6531146cc1a7c494a3e
sha256: 140707466e759d03686e8cd4c642ade858500f4982bdb791deca178f08ad7772
sha512: 3a400ca4570b580f2e4f512d1392b873e8730c71fea19edc41b9ac7c26ec2dbdf6eb5a0479791b5036a66ccf5e750bb5771aa2956802d173eec82c64345c5979
ssdeep: 6144:ENy2ibWF4RQz326+j606ao3e9RHq1al/9h8VI1oKDyVQiOK:cyY76jo3ei4/eW4VNOK
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: vvikid co ltd
Assembly Version: 4.0.6.0
InternalName: OfRTaBhkmsVUzusv.exe
FileVersion: 4.0.8.0
CompanyName: vvikid co ltd
LegalTrademarks:
Comments: Sector for math
ProductName: Calculator Sector
ProductVersion: 4.0.8.0
FileDescription: Calculator Sector
OriginalFilename: OfRTaBhkmsVUzusv.exe

Trojan.Banload.Agent also known as:

DrWebTrojan.PWS.Siggen2.44716
MicroWorld-eScanTrojan.GenericKD.42836275
Qihoo-360Generic/Trojan.PSW.9f6
McAfeeArtemis!15DD924CFD3E
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 004fb5f31 )
BitDefenderTrojan.GenericKD.42836275
K7GWTrojan ( 004fb5f31 )
BitDefenderThetaGen:NN.ZemsilF.34100.ym0@aigelxk
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataTrojan.GenericKD.42836275
KasperskyHEUR:Trojan-PSW.MSIL.Racealer.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKD.42836275
SophosMal/Generic-S
ComodoMalware@#2wsakxu572nnj
F-SecureTrojan.TR/AD.MoksSteal.jcaqr
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.15dd924cfd3eeb96
EmsisoftTrojan.Crypt (A)
IkarusTrojan.Inject
CyrenW32/MSIL_Kryptik.AIJ.gen!Eldorado
WebrootW32.Trojan.Gen
AviraTR/AD.MoksSteal.jcaqr
Antiy-AVLTrojan[Spy]/Win32.Banload
ArcabitTrojan.Generic.D28DA133
ZoneAlarmHEUR:Trojan-PSW.MSIL.Racealer.gen
MicrosoftTrojanSpy:Win32/Banload.AAA!bit
ALYacTrojan.Banload.Agent
MAXmalware (ai score=82)
MalwarebytesTrojan.Banker
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.VAB
TrendMicro-HouseCallTROJ_GEN.R057H0CCC20
YandexTrojan.Kryptik!c53obXlYcLU
FortinetMSIL/Racealer.HKO!tr.pws
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.74493398.susgen

How to remove Trojan.Banload.Agent?

Trojan.Banload.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment