Trojan

Should I remove “TrojanDownloader:Win32/Banload.BAK”?

Malware Removal

The TrojanDownloader:Win32/Banload.BAK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Banload.BAK virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
downloadbr21.sslblindado.com
ocsp.digicert.com
status.rapidssl.com

How to determine TrojanDownloader:Win32/Banload.BAK?


File Info:

crc32: 6C84F411
md5: 2bc1459ff8f37886adef032d08b93e79
name: 2BC1459FF8F37886ADEF032D08B93E79.mlw
sha1: d93a2232e7b2fd75991c465eb083bbaf244629ee
sha256: e5efbac8309cdf8a911781ff4a5e5de2b8df2369bdd6d020f4def8dd7e2a8f89
sha512: a5555c2ba3785a43c5ebaf6115b2b31df5d594ac2f5b007381d69c3f3d773acee42eb02183f8540c21a03941b6312a9f754bc71e7f656db120eb0c86425c1521
ssdeep: 24576:+KKd5LVc0TNSCE9s6OEfxTU7c4MyzNL8HLXSWozP+b37LDH0xghO+6sJc9pbR7O:aRQBVTUrtNJSTfb6X+6sJc9pbR7O1Do
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 3.3.3.4
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename:
Translation: 0x0416 0x04e4

TrojanDownloader:Win32/Banload.BAK also known as:

MicroWorld-eScanGen:Variant.Graftor.161665
FireEyeGen:Variant.Graftor.161665
McAfeeArtemis!2BC1459FF8F3
CylanceUnsafe
ZillyaDownloader.Banload.Win32.59044
SangforMalware
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
BitDefenderGen:Variant.Graftor.161665
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.ff8f37
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Dropper-gen [Drp]
KasperskyTrojan-Downloader.Win32.Banload.cvtr
AlibabaTrojanDownloader:Win32/Banload.4b53409a
NANO-AntivirusTrojan.Win32.Banload.dhyuon
ViRobotTrojan.Win32.Z.Banload.1150976
AegisLabTrojan.Win32.Banload.a!c
RisingDownloader.Banload!8.15B (TFE:5:psqx3ITFLkQ)
Ad-AwareGen:Variant.Graftor.161665
EmsisoftGen:Variant.Graftor.161665 (B)
ComodoMalware@#1zp3gbyep9hzi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_BANLOAD.AAAA
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Banload
JiangminTrojanDownloader.Banload.bmkp
AviraTR/Rogue.1150976.5
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Banload
KingsoftWin32.TrojDownloader.Banload.cv.(kcloud)
MicrosoftTrojanDownloader:Win32/Banload.BAK
ArcabitTrojan.Graftor.D27781
ZoneAlarmTrojan-Downloader.Win32.Banload.cvtr
GDataGen:Variant.Graftor.161665
CynetMalicious (score: 85)
BitDefenderThetaAI:Packer.6212DE1D21
ALYacGen:Variant.Graftor.161665
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.3836836862
PandaTrj/CI.A
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.UMS
TrendMicro-HouseCallTROJ_BANLOAD.AAAA
TencentWin32.Trojan-downloader.Banload.Hupt
YandexTrojan.DL.Banload!LvmRbYQ6WJk
eGambitGeneric.Trojan
FortinetW32/Banload.UMS!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Downloader.4bd

How to remove TrojanDownloader:Win32/Banload.BAK?

TrojanDownloader:Win32/Banload.BAK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment