Trojan

How to remove “Win32/TrojanDownloader.Banload.YHW”?

Malware Removal

The Win32/TrojanDownloader.Banload.YHW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Banload.YHW virus can do?

  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese

Related domains:

iplogger.org
meubackup.terra.com.br

How to determine Win32/TrojanDownloader.Banload.YHW?


File Info:

crc32: 00CAE66E
md5: 330adeea904a1b244338884d414364f0
name: 330ADEEA904A1B244338884D414364F0.mlw
sha1: 31d87590bc332a7c2570628bea6e4ae16f36af79
sha256: aeda2014bf5250cb3a6c32fe9da4cf97793f8849221047bf155fe515c9bc1769
sha512: 502cfc7b49b9a6ad83b2efee197966d64d61368398cd56db1e06d24dff32e0d50067f336d6a5ef1520a16171db516824a315117ee3dcfca8b54e0041d6a4152d
ssdeep: 24576:RGeaaH72A1TyI2ngxhuBKSGBFWSo5Yo4FvTWSfc:RNcQS2oO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.1.2.2
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename:
Translation: 0x0416 0x04e4

Win32/TrojanDownloader.Banload.YHW also known as:

LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.DownLoader26.35062
CylanceUnsafe
ZillyaDownloader.Banload.Win32.88670
AlibabaRansom:Win32/Blocker.1d03016a
K7GWTrojan-Downloader ( 0057060e1 )
K7AntiVirusTrojan-Downloader ( 0057060e1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.YHW
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-Ransom.Win32.Blocker.gen
BitDefenderTrojan.GenericKD.37555528
NANO-AntivirusTrojan.Win32.Banload.epkshz
MicroWorld-eScanTrojan.GenericKD.37555528
TencentMalware.Win32.Gencirc.10ba7067
SophosMal/Generic-S
ComodoMalware@#1y29w045rnj31
F-SecureTrojan.TR/Dldr.Banload.mxfeq
BitDefenderThetaAI:Packer.B21DDBAC19
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Infected.th
FireEyeTrojan.GenericKD.37555528
EmsisoftTrojan.GenericKD.37555528 (B)
JiangminTrojan.Blocker.nij
AviraTR/Dldr.Banload.mxfeq
Antiy-AVLTrojan/Generic.ASMalwS.2B23997
MicrosoftPWS:Win32/Zbot!ml
GDataTrojan.GenericKD.37555528
McAfeeArtemis!330ADEEA904A
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.Banker
PandaTrj/GdSda.A
YandexTrojan.DL.Banload!Yhydcbnlib8
IkarusTrojan-Downloader.Win32.Banload
MaxSecureTrojan.Malware.1129961.susgen
FortinetW32/Banload.YHW!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/TrojanDownloader.Banload.YHW?

Win32/TrojanDownloader.Banload.YHW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment