Trojan

TrojanDownloader:Win32/Banload.IU removal

Malware Removal

The TrojanDownloader:Win32/Banload.IU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Banload.IU virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Banload.IU?


File Info:

name: A4A2A55CE9FC7689DC8D.mlw
path: /opt/CAPEv2/storage/binaries/097460ed794e9fb7c3ba24f10c79a1b222434a6e691f222677f0e95bce45883c
crc32: EE86FDD6
md5: a4a2a55ce9fc7689dc8d18ba5f3677f4
sha1: de2f30a095d2e180110c8de74eecf5a147cb21a8
sha256: 097460ed794e9fb7c3ba24f10c79a1b222434a6e691f222677f0e95bce45883c
sha512: ecf1515641fe549f969260e280d90323ea1616fc2c3b2e0f8257f972f50efdd561c347a94d28cdbdd60e9b34d074b2a729d6fe8c62255788bef812ec03f41b68
ssdeep: 3072:+UwXQvupGBTtsPGIvDGzUB7n79EyuGodsYVwuCI7/GJb1VYZ:jvpkGdnFGodsYVwuCVVk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196C35B63F1C188B7D3041A799C06B259A76EBE222E27865FB7F42D4DDEB92C0641C1C7
sha3_384: f312c834b34f8ad379ef3de76b730a20016255dc8264bf8d58bda453579f7e57e546ef5cd1418a83e821d77d7b3a8850
ep_bytes: 558becb9180000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

TrojanDownloader:Win32/Banload.IU also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.l7D5
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad.42431
MicroWorld-eScanGen:Variant.Doina.19649
FireEyeGeneric.mg.a4a2a55ce9fc7689
SkyhighBehavesLike.Win32.Wabot.ch
McAfeeGenDownloader.c
MalwarebytesGeneric.Malware.AI.DDS
ZillyaBackdoor.Krap.Win32.3778
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDownloader:Win32/Banload.6162cfff
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
ArcabitTrojan.Doina.D4CC1
VirITTrojan.Win32.Banload.ANRM
SymantecDownloader
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.BDA
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Adload-188
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Doina.19649
NANO-AntivirusTrojan.Win32.Delphi.eecbxr
AvastWin32:Banload-GJJ [Trj]
TencentMalware.Win32.Gencirc.10bdba2a
EmsisoftGen:Variant.Doina.19649 (B)
VIPREGen:Variant.Doina.19649
TrendMicroMal_Banker15
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Agent.bgfe
WebrootW32.Malware.Downloader
VaristW32/Delfloader.B.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Agent
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.Agent.~JH4@1ohy0k
MicrosoftTrojanDownloader:Win32/Banload.IU
ViRobotTrojan.Win32.A.Downloader.113862
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Doina.19649
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R143685
VBA32TrojanDownloader.Agent
ALYacGen:Variant.Doina.19649
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Nabload.DNI
TrendMicro-HouseCallMal_Banker15
RisingDownloader.Banload!8.15B (TFE:4:dLGY9Bhh1zI)
YandexTrojan.GenAsa!wgI++b9QuZI
IkarusTrojan-Downloader.Win32.Brig
MaxSecureTrojan.Malware.1299279.susgen
FortinetW32/Generic.AC.5A69E!tr
AVGWin32:Banload-GJJ [Trj]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Banload.IU?

TrojanDownloader:Win32/Banload.IU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment