Trojan

TrojanDownloader:Win32/Banload.AOU malicious file

Malware Removal

The TrojanDownloader:Win32/Banload.AOU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Banload.AOU virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Arabic (Oman)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine TrojanDownloader:Win32/Banload.AOU?


File Info:

crc32: 7AFD4FAC
md5: 74923c322f7f75fd7eb86a6ade2bc085
name: 74923C322F7F75FD7EB86A6ADE2BC085.mlw
sha1: 34c363adffff574a1e0d25a150d58eea24a9b307
sha256: c7b8a1180796e7ce70e6efc0f229dc17a3588841aa4d7f011c814ae6ffda17fd
sha512: cb66374c2ed8905c48c46972d16e0fa1db1c15f2671052a8d880001ce3a19bf0b31678d26d06d534de5ed260699dbdcf52fda3f26e4fe37a4239ec6ba360379d
ssdeep: 6144:F2m3XmYKefv8I/HOSbDKnGPcSlAdq302Hk9j781CSQi7DGurcaDLG4Yzb2slRqZ:FLmY9vwGP7W2E9o1hx7JrHZqHlRtaj
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 9, 4
FileVersion: 3, 3, 9, 4
FileDescription:
Translation: 0x0809 0x04b0

TrojanDownloader:Win32/Banload.AOU also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen4.33006
MicroWorld-eScanTrojan.Generic.8044978
FireEyeGeneric.mg.74923c322f7f75fd
ALYacTrojan.Generic.8044978
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 700000111 )
BitDefenderTrojan.Generic.8044978
K7GWTrojan ( 700000111 )
Cybereasonmalicious.22f7f7
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/KillAV.NOP
TrendMicro-HouseCallTROJ_GEN.R002C0PLL20
AvastAutoIt:Agent-K [Trj]
KasperskyHEUR:Trojan.Script.Generic
AlibabaTrojan:Win32/KillAV.29d8fedb
NANO-AntivirusTrojan.Win32.TrjGen.bbfesr
AegisLabTrojan.Win32.Yakes.4!c
Ad-AwareTrojan.Generic.8044978
SophosMal/Generic-R + W32/AutoIt-QR
ComodoMalware@#28ai07ci42ubi
F-SecureTrojan.TR/Dropper.Gen
TrendMicroTROJ_GEN.R002C0PLL20
McAfee-GW-EditionBehavesLike.Win32.Spyware.gc
EmsisoftTrojan.Generic.8044978 (B)
IkarusTrojan-Downloader.Win32.Banload
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanDownloader:Win32/Banload.AOU
ArcabitTrojan.Generic.D7AC1B2
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Generic.8044978
CynetMalicious (score: 100)
McAfeeGeneric.dx!74923C322F7F
VBA32TrojanPSW.Panda
MalwarebytesMalware.AI.4257715681
PandaTrj/OCJ.A
APEXMalicious
TencentWin32.Trojan.Yakes.bsdu
SentinelOneStatic AI – Malicious PE
FortinetW32/AutoIt.NOP!tr.pws
AVGAutoIt:Agent-K [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Trojan.Multi.daf

How to remove TrojanDownloader:Win32/Banload.AOU?

TrojanDownloader:Win32/Banload.AOU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment