Trojan

TrojanDownloader:Win32/Banload.AJO (file analysis)

Malware Removal

The TrojanDownloader:Win32/Banload.AJO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Banload.AJO virus can do?

  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Uses Windows utilities for basic functionality
  • Network activity contains more than one unique useragent.
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Banload.AJO?


File Info:

crc32: F037363F
md5: 59613b38bb8f462afb089328f2b1d428
name: 59613B38BB8F462AFB089328F2B1D428.mlw
sha1: 6821114986bde6e0826a648347c9a37974fa5236
sha256: 8e94a5a25323e3dce93e74e6bf6a555335a13ed20391d3a67e13d6170df97bf4
sha512: b4496eb3e92faee6c1a5d30e187683ca283c36dd8e31d16df8fd60127fd5dd48d80b5cb7626fd6ff877be45bc91112978260cf655dddeaf3dbc682e2b675f728
ssdeep: 768:Ay1q04Q25w8ZUtsBC/9a9cv9A8ohc9nrqj7oFormISLqvsPKZy7C8x:31q04Q26qBClaN87rqj7GZLQsPKw/x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Banload.AJO also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.42818
FireEyeGeneric.mg.59613b38bb8f462a
ALYacGen:Variant.Symmi.42818
CylanceUnsafe
ZillyaDownloader.Banload.Win32.36611
SangforMalware
K7AntiVirusTrojan ( 005548441 )
BitDefenderGen:Variant.Symmi.42818
K7GWTrojan ( 005548441 )
Cybereasonmalicious.8bb8f4
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyHEUR:Trojan-Downloader.Win32.Generic
AlibabaTrojanDownloader:Win32/Banload.b4777947
NANO-AntivirusTrojan.Win32.Delphi.kqvzm
ViRobotTrojan.Win32.Z.Banload.55808.O
AegisLabTrojan.Win32.Generic.a!c
Ad-AwareGen:Variant.Symmi.42818
EmsisoftGen:Variant.Symmi.42818 (B)
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
F-SecureTrojan.TR/Dldr.Delphi.Gen
DrWebTrojan.DownLoader5.52729
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTSPY_BANKER.SMUA
McAfee-GW-EditionBehavesLike.Win32.Android.qh
SophosTroj/DwnLdr-JSJ
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Generic.uem
WebrootW32.Malware.Gen
AviraTR/Dldr.Delphi.Gen
eGambitGeneric.Downloader
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Genome
MicrosoftTrojanDownloader:Win32/Banload.AJO
ArcabitTrojan.Symmi.DA742
SUPERAntiSpywareTrojan.Agent/Gen-Banload
ZoneAlarmHEUR:Trojan-Downloader.Win32.Generic
GDataGen:Variant.Symmi.42818
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Banload.C153347
McAfeeGenericR-DAG!59613B38BB8F
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.256535544
PandaTrj/Genetic.gen
ZonerTrojan.Win32.8272
ESET-NOD32a variant of Generik.UYJJXG
TrendMicro-HouseCallTSPY_BANKER.SMUA
RisingDownloader.Banload!8.15B (TFE:4:lSALSlt9EkO)
YandexTrojan.GenAsa!nDY/JQHEURg
IkarusTrojan-Downloader.Win32.Genome
FortinetW32/DwnLdr.JSJ!tr
BitDefenderThetaGen:NN.ZelphiF.34804.dGW@aCh5BQnG
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/Malware.QVM05.Gen

How to remove TrojanDownloader:Win32/Banload.AJO?

TrojanDownloader:Win32/Banload.AJO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment