Trojan

Win32/TrojanDownloader.Banload.QHP removal instruction

Malware Removal

The Win32/TrojanDownloader.Banload.QHP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Banload.QHP virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Portuguese
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/TrojanDownloader.Banload.QHP?


File Info:

name: FFDFE0788B7AACA6D958.mlw
path: /opt/CAPEv2/storage/binaries/d679957740ddf6cd32670628144f5b8efd61440327564a183dfd55fe053e1d8c
crc32: C38AD218
md5: ffdfe0788b7aaca6d95862553e2767c3
sha1: 8ff048da58876a816ff5650bc654a981c55c0594
sha256: d679957740ddf6cd32670628144f5b8efd61440327564a183dfd55fe053e1d8c
sha512: f6c1ff1b4c8832d1f8db882f321f88280b702296d546dad8c665a28bbf37a3faf8a4fe7de3483676f06738117f28e8f44116626a8e9c3a858947e72505094698
ssdeep: 49152:3GtKaFSWs6Qx+B661tD+MWGqJY3WLp2ZYIB5:cKMk+g6O9G6YmLmYIB5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2D54A13B289643AE1671B368C3786549C3B7F603E269C5F6FF41D0C0F38641AD7AA96
sha3_384: cad9c91d697cc10078002573d7bc565ecfa412ce1feaf78bc8e00112349832a485b8ce737668e91dda1faf0bdaa5cd7f
ep_bytes: 558bec83c4f053b8dc396500e8bfe0da
timestamp: 2011-08-03 01:02:22

Version Info:

CompanyName:
FileDescription:
FileVersion: 4.3.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 4.3.0.0
Comments:
Translation: 0x0441 0x04e4

Win32/TrojanDownloader.Banload.QHP also known as:

LionicTrojan.Win32.Badur.lxY1
McAfeeGenericR-HLN!FFDFE0788B7A
CylanceUnsafe
ZillyaTrojan.Banload.Win32.1633
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.a58876
BitDefenderThetaGen:NN.ZelphiF.34682.Vo0@aCiKPnaO
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/TrojanDownloader.Banload.QHP
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Generic
NANO-AntivirusTrojan.Win32.SMSSend.cgisna
CynetMalicious (score: 100)
AvastWin32:Malware-gen
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.SMSSend.3840
McAfee-GW-EditionBehavesLike.Win32.Dropper.vm
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ffdfe0788b7aaca6
SophosMal/Generic-S
APEXMalicious
JiangminTrojanDownloader.Banload.auol
AviraHEUR/AGEN.1237710
Antiy-AVLTrojan/Generic.ASMalwS.D56
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Scar.R9524
VBA32TrojanDropper.Dapato
MalwarebytesMalware.Heuristic.1003
RisingMalware.Undefined!8.C (TFE:4:YhxW74x0AmU)
YandexTrojan.GenAsa!FnqR73+rbSc
IkarusTrojan.Rogue
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.TKT!tr.dldr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Win32/TrojanDownloader.Banload.QHP?

Win32/TrojanDownloader.Banload.QHP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment