Trojan

Win32/TrojanDownloader.Banload.XVH (file analysis)

Malware Removal

The Win32/TrojanDownloader.Banload.XVH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Banload.XVH virus can do?

  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/TrojanDownloader.Banload.XVH?


File Info:

name: 6A13240606694E5A04C2.mlw
path: /opt/CAPEv2/storage/binaries/d76e97cadd423e29fb4fdba174ad5ed2f523df81ec448dc979f0a5db5b8e9c2e
crc32: 28630AEE
md5: 6a13240606694e5a04c2053e6108a14a
sha1: 09e76a9958733620c1c59d46497d80db291caced
sha256: d76e97cadd423e29fb4fdba174ad5ed2f523df81ec448dc979f0a5db5b8e9c2e
sha512: 337e5d2ca1869715486df5ba67c19cf2932726e6081e8b9d55704864fc68e54e468681a3bc1413e79c79c22ed7c6139814800de80cc035c26f55bbe8fefe87a6
ssdeep: 12288:tjweUWQrWs8QPinFupDUsrjh8jRRVfZhpdn:Z0WQ0QPFp3PhYp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125E408D25960393BC3EADEF848E60DB8CA5F7A70271654F5D5F629083A2C190276E34F
sha3_384: 0cf2ac473ab819f59f072afa9e8704bc70a7a87c788727857cfd2978e30ec6b5bcd9cd8605172d88c534d85027691f0b
ep_bytes: 8bc88bd38bc5e8b40000004383c60483
timestamp: 2010-08-01 10:32:37

Version Info:

0: [No Data]

Win32/TrojanDownloader.Banload.XVH also known as:

LionicTrojan.Win32.BestaFera.7!c
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 005078da1 )
AlibabaTrojanBanker:Win32/BestaFera.7a2f0842
K7GWTrojan-Downloader ( 005078da1 )
Cybereasonmalicious.958733
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.XVH
APEXMalicious
KasperskyTrojan-Banker.Win32.BestaFera.zax
NANO-AntivirusTrojan.Win32.BestaFera.eykhhb
AvastWin32:Malware-gen
TencentWin32.Trojan-banker.Bestafera.Wnwd
ComodoMalware@#2xamqawu6hc0d
DrWebBackDoor.Attack.3075
ZillyaTrojan.BestaFera.Win32.10330
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.6a13240606694e5a
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1229625
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.4689
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ZoneAlarmTrojan-Banker.Win32.BestaFera.zax
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.BestaFera.C2420636
Acronissuspicious
McAfeeGenericR-LWN!6A1324060669
VBA32TrojanBanker.BestaFera
MalwarebytesMalware.AI.4260529722
RisingSpyware.Banker!1.ABA2 (CLASSIC)
YandexTrojan.GenAsa!KzTpLq2y7Qo
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banload.XVH!tr
BitDefenderThetaGen:NN.ZelphiF.34582.OGW@aGFJtIk
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/TrojanDownloader.Banload.XVH?

Win32/TrojanDownloader.Banload.XVH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment