Trojan

TrojanDownloader:Win32/Banload.BGW (file analysis)

Malware Removal

The TrojanDownloader:Win32/Banload.BGW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Banload.BGW virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Banload.BGW?


File Info:

crc32: 1267DD59
md5: 617b473e44b3279c5b5b9eddb47a8431
name: 617B473E44B3279C5B5B9EDDB47A8431.mlw
sha1: 21b45914cea6c2f7820414e29cbc3f82fe6dca43
sha256: ddc6aba5920051af7a0736e934fb92f57fc4c6d3ef6e6c6dd4c53c8fab1fc391
sha512: d46147e4c9a195690cc0063206fde51b3b5705064068b5b2e1b2380c0e619a23a3897436c9dfcc28ba2e3d5528ea3d2639558f0a0bcfff963f493636f8502d71
ssdeep: 24576:T8lO9GoW5AxMobNeQYP0djNeE6CFtvX5/C4iA29KFlTU+Zp76:TbFzYP0djR6CFtvZiA24TP776
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Banload.BGW also known as:

MicroWorld-eScanGen:Variant.Symmi.69792
FireEyeGeneric.mg.617b473e44b3279c
ALYacGen:Variant.Symmi.69792
CylanceUnsafe
AegisLabTrojan.Win32.Delf.a!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Symmi.69792
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e44b32
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Banker-MYS [Trj]
KasperskyTrojan-Downloader.Win32.Delf.kloh
NANO-AntivirusTrojan.Win32.Delf.elcmjv
RisingTrojan.Generic@ML.96 (RDML:GpBllUjUFsmUEbwZMZe2Qg)
Ad-AwareGen:Variant.Symmi.69792
EmsisoftGen:Variant.Symmi.69792 (B)
ComodoTrojWare.Win32.TrojanDownloader.Banload.DAQ@61edgs
F-SecureHeuristic.HEUR/AGEN.1118020
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_BANLOAD.YWNST
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Banload
AviraHEUR/AGEN.1118020
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojanDownloader:Win32/Banload.BGW
ArcabitTrojan.Symmi.D110A0
ZoneAlarmTrojan-Downloader.Win32.Delf.kloh
GDataGen:Variant.Symmi.69792
CynetMalicious (score: 85)
AhnLab-V3Downloader/Win32.Delf.C1727908
McAfeeTrojan-FKXW!617B473E44B3
MAXmalware (ai score=81)
VBA32BScope.TrojanBanker.ChePro
MalwarebytesMalware.AI.4206996100
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.XTI
TrendMicro-HouseCallTROJ_BANLOAD.YWNST
TencentWin32.Trojan-downloader.Delf.Wmsx
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Banload.XTF!tr
BitDefenderThetaAI:Packer.08542BAE21
AVGWin32:Banker-MYS [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.bce

How to remove TrojanDownloader:Win32/Banload.BGW?

TrojanDownloader:Win32/Banload.BGW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment