Trojan

How to remove “TrojanDownloader:Win32/Banload.BFZ”?

Malware Removal

The TrojanDownloader:Win32/Banload.BFZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Banload.BFZ virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
displayexpress.com

How to determine TrojanDownloader:Win32/Banload.BFZ?


File Info:

crc32: D18D5EEB
md5: f0351cdb4083d6275534d912769726a6
name: F0351CDB4083D6275534D912769726A6.mlw
sha1: c736c79849576b057263873807635d49190f27cb
sha256: 38a96c239dc7f89cd6696e5137eb60b9c508eeca60a0c652f2147997c1152f85
sha512: 2d2264890e50cc12192e2cf44b054d315bd47645fc4abdb1618ab9e7574d699ef8181943431164c344b5a784fa6fcf0016d427afa82eabecdc5ab6bab0e8ba47
ssdeep: 12288:/+FjcVjldc0VPbtcW5A68jAII1Zw7C1/7SUCCcrtzoPHEKpAskTUqnD49u:/WCpVPbtcW5A6gSrw2NaCuOfHplkTU+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Banload.BFZ also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jacard.196920
FireEyeGeneric.mg.f0351cdb4083d627
ALYacGen:Variant.Jacard.196920
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005708721 )
BitDefenderGen:Variant.Jacard.196920
K7GWTrojan-Downloader ( 005708721 )
Cybereasonmalicious.b4083d
CyrenW32/Trojan.IBNT-7850
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Banker-MPF [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojanDownloader:Win32/Banload.ca67fb20
NANO-AntivirusTrojan.Win32.Delphi.dzacep
ViRobotTrojan.Win32.Z.Banload.642560
Ad-AwareGen:Variant.Jacard.196920
SophosMal/Generic-R + Troj/Banloa-CIO
ComodoMalware@#2fdyihxhl6sig
F-SecureHeuristic.HEUR/AGEN.1128394
ZillyaDownloader.Delf.Win32.46232
TrendMicroTROJ_BANLOAD.NNH
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
EmsisoftGen:Variant.Jacard.196920 (B)
IkarusTrojan-Downloader.Win32.Banload
AviraHEUR/AGEN.1128394
eGambitUnsafe.AI_Score_100%
MAXmalware (ai score=82)
Antiy-AVLTrojan[Downloader]/Win32.Delf
MicrosoftTrojanDownloader:Win32/Banload.BFZ
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Jacard.D30138
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Jacard.196920
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1310814
McAfeeTrojan-FHMJ!F0351CDB4083
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.WTT
TrendMicro-HouseCallTROJ_BANLOAD.NNH
RisingDownloader.Banload!8.15B (CLOUD)
YandexTrojan.DL.Delf!OoJ1NjEee7Y
SentinelOneStatic AI – Suspicious PE
FortinetW32/TrojanDldr.WPN!tr
BitDefenderThetaGen:NN.ZelphiF.34804.NGW@aumtbVm
AVGWin32:Banker-MPF [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM05.1.Malware.Gen

How to remove TrojanDownloader:Win32/Banload.BFZ?

TrojanDownloader:Win32/Banload.BFZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment