Trojan

Trojan.Binder (file analysis)

Malware Removal

The Trojan.Binder is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Binder virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup

Related domains:

zh2.ddns.net

How to determine Trojan.Binder?


File Info:

crc32: 98420D18
md5: 382d5863f3ce1b5a2230a380cffbddb7
name: 382D5863F3CE1B5A2230A380CFFBDDB7.mlw
sha1: 450bfb8654c363242979ba1fb0c1854c61d95aa6
sha256: 8ba6eca5fc9bd451306f79b17beb58ab634b11bdca6824450d22d307a996cdad
sha512: 823ac76685b651c4878e0211b5ca9048fb739e05af4c26e40e6173a812b3753867a4bff09fdd3f17c128714672ca28baa04a0cd30554426cfb4e8b48c5882c30
ssdeep: 24576:cyZwMyADr3BBl0jADfVYC/kyIXD7Vn8AbTuV3qzTucv1t29:LOF0RBl0Id/oz5nxTeYuc9t2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.10586.0 (th2_release.151029-1700)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.10586.0
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE
Translation: 0x0409 0x04b0

Trojan.Binder also known as:

K7AntiVirusTrojan ( 004915961 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTool.Binder.2
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Binder
ALYacTrojan.GenericKD.43578104
CylanceUnsafe
ZillyaTrojan.Generic.Win32.626246
AlibabaBackdoor:MSIL/Bladabindi.1252e5f3
K7GWTrojan ( 004915961 )
Cybereasonmalicious.3f3ce1
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-6298576-0
KasperskyUDS:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.43578104
NANO-AntivirusTrojan.Win32.Bladabindi.emncvd
MicroWorld-eScanTrojan.GenericKD.43578104
TencentWin32.Trojan.Generic.Liqv
Ad-AwareTrojan.GenericKD.43578104
SophosMal/Generic-S
ComodoMalware@#3ssbt4s45g2lg
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R014C0WDO21
McAfee-GW-EditionGeneric.axu
FireEyeTrojan.GenericKD.43578104
EmsisoftTrojan.GenericKD.43578104 (B)
SentinelOneStatic AI – Malicious SFX
JiangminRiskTool.MSIL.cflm
AviraTR/Agent.wmfdq
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.24903ED
MicrosoftBackdoor:MSIL/Bladabindi.AJ
GDataTrojan.GenericKD.43578104
McAfeeArtemis!382D5863F3CE
MAXmalware (ai score=100)
MalwarebytesTrojan.Facebook
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R014C0WDO21
RisingTrojan.Generic@ML.100 (RDML:oOjggDScEoAM4txbA6y1Lw)
YandexTrojan.Agent!cXMNbwZincY
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.RMO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Binder?

Trojan.Binder removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment