Trojan

What is “Win32/TrojanDownloader.Banload.YTX”?

Malware Removal

The Win32/TrojanDownloader.Banload.YTX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Banload.YTX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Quantum malware family
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Win32/TrojanDownloader.Banload.YTX?


File Info:

name: 4CEF533F027160A71616.mlw
path: /opt/CAPEv2/storage/binaries/c5ccf23a174e9eaa99d904fd6d9af57bbd7d9b8c789c0d2c27410ffb1125ce24
crc32: 594FAF21
md5: 4cef533f027160a71616af8c7a24df6d
sha1: e188e8bd8acdad501b5ede7eee47027a3be9586a
sha256: c5ccf23a174e9eaa99d904fd6d9af57bbd7d9b8c789c0d2c27410ffb1125ce24
sha512: 7adb7bb14b63e2ba0d35bce8fdf26396042d1bd67e2c106ae227058642979769024d531e06af7fb0f8d5dc481e4f61467468ea97e83b40acb7e0a89173009f8a
ssdeep: 196608:0OTbGLkMax7ZnCINfIkhBG1rjQlF0GA9utBo9R:0OOFatZnrNfIkhBG1rjQlF0GA9uLg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EAD66D22F284903FC4671B36483B9754683BBB603E2A9C4B6BF46D4C1F357817926E97
sha3_384: a1d269abb4bb459e0f78c013a77bea6cadbf0860495ec02dc7ba0b29c091daf5e90bfe414b101f1f9a01b4caebf504c5
ep_bytes: 558bec83c4f0b878f2ec00e8141c52ff
timestamp: 2022-05-05 02:55:11

Version Info:

CompanyName: Razzing HEAD Display Folling
FileDescription: Razzing HEAD Display Folling
FileVersion: 44.76.8754.32
InternalName: Razzing HEAD Display Folling
LegalCopyright: Razzing HEAD Copyright (C)
LegalTrademarks: Razzing HEAD Copyright (C)
OriginalFilename: Razzing HEAD Display Folling
ProgramID: Razzing HEAD Display Folling
ProductName: Razzing HEAD Display Folling
ProductVersion: 44.76.8754.32
Comments: Razzing HEAD Display Folling
Translation: 0x0409 0x04e4

Win32/TrojanDownloader.Banload.YTX also known as:

MicroWorld-eScanGen:Variant.Zusy.423445
FireEyeGen:Variant.Zusy.423445
McAfeeArtemis!4CEF533F0271
K7AntiVirusTrojan-Downloader ( 005923a71 )
K7GWTrojan-Downloader ( 005923a71 )
BitDefenderThetaGen:NN.ZelphiF.34638.@V0@aGZX71fO
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.YTX
BitDefenderGen:Variant.Zusy.423445
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Variant.Zusy.423445
EmsisoftGen:Variant.Zusy.423445 (B)
F-SecureTrojan.TR/Dldr.Banload.bdmnt
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
GDataGen:Variant.Zusy.423445
AviraTR/Dldr.Banload.bdmnt
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Zusy.D67615
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
ALYacGen:Variant.Zusy.423445
MAXmalware (ai score=87)
MalwarebytesTrojan.Downloader
RisingSpyware.Delf!8.12D (TFE:dGZlOgRdypZZ+0MGTg)
IkarusTrojan-Downloader.Win32.Banload
FortinetW32/Banload.YTX!tr
AVGWin32:DropperX-gen [Drp]

How to remove Win32/TrojanDownloader.Banload.YTX?

Win32/TrojanDownloader.Banload.YTX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment