Trojan

TrojanDownloader:Win32/Banload.AYX removal guide

Malware Removal

The TrojanDownloader:Win32/Banload.AYX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Banload.AYX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

edaysch.ru
apps.identrust.com
crl.identrust.com
r3.o.lencr.org

How to determine TrojanDownloader:Win32/Banload.AYX?


File Info:

crc32: 5D9EA991
md5: be7233057160d12291392f37a2555e22
name: BE7233057160D12291392F37A2555E22.mlw
sha1: b4b54ae4fc4e3892f2e414dca72e23b90c907e36
sha256: 0eb01bdbeba4d25c584fff77439bca93af2e88628d9940d5d1e7747ff9d4ab4a
sha512: 5ce7e859b1c9564b798387fd3d215206f1dad6892fd3a19036303be92b588c8de210f4e2dd9472f40f480d2ba00bd6036e609e345361258b53b21f5403549328
ssdeep: 12288:pkEEeS7QdHCEagB1ZnsIVffhzVuBP5t0ipjoMPBaBSH:CeVH9rBphz65DbP+M
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

TrojanDownloader:Win32/Banload.AYX also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader11.25730
MicroWorld-eScanGen:Variant.Zusy.101725
FireEyeGeneric.mg.be7233057160d122
McAfeeArtemis!BE7233057160
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 004c6df71 )
BitDefenderGen:Variant.Zusy.101725
K7GWTrojan-Downloader ( 004c6df71 )
Cybereasonmalicious.57160d
BitDefenderThetaAI:Packer.8AB6380121
CyrenW32/Delf.FS.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
AlibabaTrojanDownloader:Win32/Banload.c7db65a3
NANO-AntivirusTrojan.Win32.Banload.ddqhsm
AegisLabTrojan.Win32.Banload.a!c
TencentWin32.Trojan-downloader.Banload.Pijq
Ad-AwareGen:Variant.Zusy.101725
EmsisoftGen:Variant.Zusy.101725 (B)
ComodoMalware@#n5k0x344u0f
F-SecureHeuristic.HEUR/AGEN.1112446
ZillyaDownloader.Banload.Win32.58380
TrendMicroTROJ_BANLOAD.GGTT
McAfee-GW-EditionGenericR-CPE!DAE242B7EB78
SophosTroj/Bancos-BZG
IkarusTrojan-Downloader.Win32.Banload
JiangminTrojan/JboxGeneric.gzz
AviraHEUR/AGEN.1112446
Antiy-AVLTrojan[Downloader]/Win32.Banload
KingsoftWin32.TrojDownloader.Banload.cv.(kcloud)
MicrosoftTrojanDownloader:Win32/Banload.AYX
ArcabitTrojan.Zusy.D18D5D
ZoneAlarmTrojan-Downloader.Win32.Banload.cvmc
GDataGen:Variant.Zusy.101725
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Banload.R119695
VBA32TrojanDownloader.Banload
ALYacGen:Variant.Zusy.101725
MAXmalware (ai score=99)
MalwarebytesMalware.AI.4059439457
PandaTrj/Genetic.gen
ZonerTrojan.Win32.25426
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.TZM
TrendMicro-HouseCallTROJ_BANLOAD.GGTT
RisingDownloader.Banload!8.15B (TFE:5:ead9c7wzaAG)
YandexTrojan.DL.Banload!wc+edoafup4
SentinelOneStatic AI – Malicious PE
FortinetW32/TrojanDldr.XEAR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.Downloader.4fb

How to remove TrojanDownloader:Win32/Banload.AYX?

TrojanDownloader:Win32/Banload.AYX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment