Malware

Win32/Banito (file analysis)

Malware Removal

The Win32/Banito is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Banito virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Win32/Banito?


File Info:

crc32: 91CEC733
md5: 6f4566a4d3686f8d5d1932304aea9074
name: 6F4566A4D3686F8D5D1932304AEA9074.mlw
sha1: c2ca8be850dec661302a7b78b4c84a88e6e8dbdd
sha256: 2cac73f79f0f9d4853a2c51dec97174e54fde8174e82d23034b175cda0a32165
sha512: 06f33b8266032de66d2f7f83e97a7db69d3aa2e7133d5257f2920f6171ce989519db3d95bfdde0ca48e6c22bf720e017fc4bd93b94a02b8a87769967107ec5f6
ssdeep: 3072:5PaHi5TlaOm6fPNkFGgfwm2QQh+99LU2fo3k8j1bpfUjd19pcyNBNt8V9r:8CWOmFGgfw4B2qPcyNbe/r
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Copyright (C) 1992-2001 Microsoft Corp.
InternalName: Internet Online upgrade Services
FileVersion: 6.08.3750
CompanyName: Microsoft Corporation
Comments: Internet Online upgrade Services Access
ProductName: Online Services
ProductVersion: 6.08.3750
FileDescription: Internet Components Automatic Upgrade
OriginalFilename: Internet Online upgrade Services.exe

Win32/Banito also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 003d23081 )
LionicTrojan.Win32.Sasfis.4!c
Elasticmalicious (high confidence)
DrWebTrojan.StartPage.21155
ClamAVWin.Downloader.Agent-31388
McAfeeArtemis!6F4566A4D368
CylanceUnsafe
ZillyaTrojan.Banito.Win32.100
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Sasfis.fdb85ccb
K7GWTrojan ( 003d23081 )
Cybereasonmalicious.4d3686
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Banito
APEXMalicious
AvastWin32:Small-HGY [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Sasfis.ctrh
BitDefenderGen:Trojan.Heur.hm1@sv@ICHdjy
NANO-AntivirusTrojan.Win32.Banito.oqdhb
MicroWorld-eScanGen:Trojan.Heur.hm1@sv@ICHdjy
TencentWin32.Trojan.Sasfis.Wqwz
Ad-AwareGen:Trojan.Heur.hm1@sv@ICHdjy
SophosML/PE-A
BitDefenderThetaAI:Packer.5618725D1D
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionNew Malware.x
FireEyeGeneric.mg.6f4566a4d3686f8d
EmsisoftGen:Trojan.Heur.hm1@sv@ICHdjy (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_88%
KingsoftWin32.Heur.KVM006.a.(kcloud)
MicrosoftTrojan:Win32/MultiInjector.C!rfn
ArcabitTrojan.Heur.EDD26CD
ZoneAlarmTrojan.Win32.Sasfis.ctrh
GDataGen:Trojan.Heur.hm1@sv@ICHdjy
Acronissuspicious
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=100)
PandaTrj/CI.A
RisingTrojan.Win32.Nodef.jng (CLASSIC)
YandexTrojan.Agent!/RfvD/fTfbA
IkarusVirus.Win32.Delf
FortinetW32/Sasfis.CTRH!tr
AVGWin32:Small-HGY [Trj]
Paloaltogeneric.ml

How to remove Win32/Banito?

Win32/Banito removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment