Trojan

Win32/TrojanDownloader.Banload.XBU removal

Malware Removal

The Win32/TrojanDownloader.Banload.XBU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Banload.XBU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/TrojanDownloader.Banload.XBU?


File Info:

name: E463B301EEAD2213C561.mlw
path: /opt/CAPEv2/storage/binaries/7d34dbdf4649190eb15cfbaa84829055cc83d9e2a8eff8677c4b508b6da24b91
crc32: CCA68390
md5: e463b301eead2213c56147eda8681a5f
sha1: 059e241947bd2d6af1f076f818dc4319e486caff
sha256: 7d34dbdf4649190eb15cfbaa84829055cc83d9e2a8eff8677c4b508b6da24b91
sha512: bcb2803efe4ab6af2ad655118202bee9f9011c5ec73e0f114319db7c8b30fe5bcb8c8e425fdd0820e7301eeae3249ba6741664595e58387a3faa17a4e1190536
ssdeep: 12288:ke7qNyR0YXJtcdHYB3i0GLGxshksgJbKvxVS6ttZN++a5ZAqgwE:kdN45tAHYB0LTuexV3N+i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T156E4AE00E351C471EABF16F04C6AB26878393DA45B6495FB52F63AAD96707E0AC3170F
sha3_384: 3a95fdf1400f7f4fb532d2bf8f31e0f573a0ec1202107f6b2889d56c33105910031591df7241eea716bf7cd43578c13c
ep_bytes: 8bff558bece8b6100100e8110000005d
timestamp: 2016-09-26 18:05:57

Version Info:

CompanyName: Raxco, Inc.
FileDescription: The program will install PerfectDisk Professional
InternalName: stub32
OriginalFilename: stub32i.exe
FileVersion: 14.0.1.2
LegalCopyright: Copyright � 2015 Raxco Corporation
ProductName: PerfectDisk Professional
ProductVersion: 14.0.1.2
Translation: 0x0409 0x04b0

Win32/TrojanDownloader.Banload.XBU also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.Dropper.jc
McAfeeArtemis!E463B301EEAD
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.947bd2
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Banload.XBU
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.MlwGen.eibtvi
AvastWin32:Dropper-gen [Drp]
F-SecureTrojan.TR/Crypt.ZPACK.hbnzq
TrendMicroMal_MiliCry-1h
FireEyeGeneric.mg.e463b301eead2213
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.hbnzq
MicrosoftTrojan:Win32/Dynamer!ac
ZoneAlarmUDS:DangerousObject.Multi.Generic
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2066123
VBA32BScope.Trojan.Yakes
MalwarebytesMachineLearning/Anomalous.97%
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_MiliCry-1h
RisingTrojan.Generic@AI.90 (RDML:KikVRVD187f3khfQT28Cxg)
YandexTrojan.DL.Banload!um2jdU8p4Lg
IkarusTrojan-Downloader.Win32.Banload
FortinetW32/Banload.XBU!tr.dldr
AVGWin32:Dropper-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/TrojanDownloader.Banload.XBU?

Win32/TrojanDownloader.Banload.XBU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment