Trojan

How to remove “Win32/TrojanDownloader.Banload.XWZ”?

Malware Removal

The Win32/TrojanDownloader.Banload.XWZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Banload.XWZ virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings

Related domains:

elital.com
apps.identrust.com
crl.identrust.com
r3.o.lencr.org

How to determine Win32/TrojanDownloader.Banload.XWZ?


File Info:

crc32: 11013724
md5: baa8b730f165e56c6917e1dca4f33b21
name: BAA8B730F165E56C6917E1DCA4F33B21.mlw
sha1: 2230ed7418c8609140e6fb2c582f1133bea77593
sha256: d3fe47e91c3927183a72a879320a5f86d853c6505339e17bba4ff93e80edbd47
sha512: 655e194bd23ddf9726032c6f405bd20b8838f9560eb017b05361e7c918cdc0f06cd518a2874d7ad9f71cd1c2d12d3c4e0a2cd5c888b704c1d5a8160aeef3e870
ssdeep: 24576:/1jPFuoVj/iSXud1Fv5GMGGw8HHDBYSUADvoaJgn2efQ+Qzm/s7Ynh1N0qW:1FpU1L1nDaSU0gN2QFPfi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/TrojanDownloader.Banload.XWZ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.53598
MicroWorld-eScanGen:Variant.Zusy.327223
ALYacGen:Variant.Zusy.327223
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 0050a7e51 )
BitDefenderGen:Variant.Zusy.327223
K7GWTrojan-Downloader ( 0050a7e51 )
Cybereasonmalicious.0f165e
BitDefenderThetaGen:NN.ZelphiF.34804.lUW@aKthimai
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Vobfus.gen
AlibabaTrojanDownloader:Win32/Banload.5ce771b1
NANO-AntivirusTrojan.Win32.Banload.eybyfc
AegisLabTrojan.Win32.Generic.4!c
RisingDownloader.Banload!8.15B (CLOUD)
Ad-AwareGen:Variant.Zusy.327223
EmsisoftGen:Variant.Zusy.327223 (B)
ComodoMalware@#90wjle93kam4
F-SecureHeuristic.HEUR/AGEN.1114731
ZillyaDownloader.Banload.Win32.78594
TrendMicroTROJ_GEN.R002C0PLL20
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
FireEyeGeneric.mg.baa8b730f165e56c
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Vobfus.tcf
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1114731
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojanDownloader:Win32/Banload!rfn
ArcabitTrojan.Zusy.D4FE37
ZoneAlarmHEUR:Trojan.Win32.Vobfus.gen
GDataGen:Variant.Zusy.327223
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C1885900
McAfeeGenericRXFX-RC!BAA8B730F165
MAXmalware (ai score=100)
VBA32Trojan.Inject
MalwarebytesTrojan.Banload
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.XWZ
TrendMicro-HouseCallTROJ_GEN.R002C0PLL20
TencentWin32.Trojan.Dldr.Piaa
YandexTrojan.GenAsa!5DRej9nUClo
IkarusTrojan-Downloader.Win32.Banload
FortinetW32/Banload.XWZ!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/TrojanDownloader.Banload.XWZ?

Win32/TrojanDownloader.Banload.XWZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment