Trojan

About “TrojanDownloader:Win32/Banload!H” infection

Malware Removal

The TrojanDownloader:Win32/Banload!H is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Banload!H virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine TrojanDownloader:Win32/Banload!H?


File Info:

name: 2F5097094904226D1FBE.mlw
path: /opt/CAPEv2/storage/binaries/1dc3faf8b9958ee61e402bd3a04ab1282b84b3856efe65964c43fe12c8c1f097
crc32: 830A3DEB
md5: 2f5097094904226d1fbe61f93c575bf5
sha1: 9ca13f03a2aacd77cfe0368cc08639d23a96f8cd
sha256: 1dc3faf8b9958ee61e402bd3a04ab1282b84b3856efe65964c43fe12c8c1f097
sha512: 40ef8a78af1aa14d598611579128f64473e29d5a90847b7273a428b9559f24502b194cea1699ad4af952b3344e2b6a510c2109a43f8a14907b6fe58917040dee
ssdeep: 6144:a8MF0esAlZG+wPl0cmDxn1qfDOqr9C4M57PDp81qQRPUWMNDuWqmjMBIlpJ:xMzsAbGTl0of6qxzJP7MN6W+e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0847D72F6D18437C273267C8C5B9368AC3DBE503E2968463BE92D4C5F39781356A293
sha3_384: 67b6405acd491ff42341ab613c33186eff5d2e25823964fc1c302464ed777c7b3dad2bd4e56095a700d04980a6521666
ep_bytes: 558becb90a0000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

TrojanDownloader:Win32/Banload!H also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.l31s
MicroWorld-eScanTrojan.Downloader.Banload.OHR
FireEyeGeneric.mg.2f5097094904226d
Skyhighgeneric!bg.ua
McAfeegeneric!bg.ua
MalwarebytesBanload.Trojan.Downloader.DDS
ZillyaTrojan.Banbra.Win32.25857
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanDownloader:Win32/Banload.3ecfe806
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.949042
VirITTrojan.Win32.Generic.AHQP
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.PKP
ClamAVWin.Downloader.49124-1
KasperskyTrojan-Downloader.Win32.Banload.aalto
BitDefenderTrojan.Downloader.Banload.OHR
NANO-AntivirusTrojan.Win32.Banload.uacp
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.1403111d
SophosMal/Behav-130
F-SecureTrojan.TR/Dldr.Delphi.Gen
DrWebTrojan.DownLoad1.8685
VIPRETrojan.Downloader.Banload.OHR
TrendMicroCryp_Banker-6
EmsisoftTrojan.Downloader.Banload.OHR (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Banload.smp
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Dldr.Delphi.Gen
VaristW32/Trojan.CSR.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Banload
KingsoftWin32.Troj.Unknown.a
MicrosoftTrojanDownloader:Win32/Banload.gen!H
XcitiumTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
ArcabitTrojan.Downloader.Banload.OHR
ViRobotTrojan.Win32.Downloader.399360.C
ZoneAlarmTrojan-Downloader.Win32.Banload.aalto
GDataTrojan.Downloader.Banload.OHR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Banload.C26650
BitDefenderThetaGen:NN.ZelphiF.36802.yGW@a0x75goG
ALYacTrojan.Downloader.Banload.OHR
MAXmalware (ai score=99)
VBA32BScope.Trojan.Delf
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallCryp_Banker-6
RisingTrojan.DL.Win32.Mnless.dfe (CLASSIC)
YandexTrojan.GenAsa!8zB8W+zBT1U
IkarusTrojan-Dropper.Delf
MaxSecureTrojan.Malware.761114.susgen
FortinetW32/Delf.NGS!tr.dldr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[downloader]:Win/Banload.gen!H

How to remove TrojanDownloader:Win32/Banload!H?

TrojanDownloader:Win32/Banload!H removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment