Malware

About “Win32:Bandook-B [Trj]” infection

Malware Removal

The Win32:Bandook-B [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Bandook-B [Trj] virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32:Bandook-B [Trj]?


File Info:

name: 0F7858BDAE11DCC3D9F0.mlw
path: /opt/CAPEv2/storage/binaries/d20a24cf0e355f50f33cbdd4cb19aaf8e89d9fcb9076240dc0c053ee941c625f
crc32: 160E0116
md5: 0f7858bdae11dcc3d9f06f4069f9db72
sha1: 08020844be3399a924ee6b4890300393a590eb54
sha256: d20a24cf0e355f50f33cbdd4cb19aaf8e89d9fcb9076240dc0c053ee941c625f
sha512: 6fd0af799b517395c7d4a19c7c52cc715bba28453926d0bf7bfb94e369fb56de4ace16182a8a836748b6cef3bfca7dea2528fd2e806f290edcda75a6a34b14e7
ssdeep: 3072:Qp05ARM4WXkydwwefMciQ0N5HePBhfkiT4o6Iy:QOv4WowbUKo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16BB6090992589068D8B3347251428FB7DDBCAA7237826487C7E4AF7F287C5B4B72911F
sha3_384: b67aa06a677e1f3605f82cec689e0a60b0ef9e909c338b4b09290afe54af0ce32d8c3cca0d6b12c798d9f61d2a9230ce
ep_bytes: c404ff15b08015135068d0b615138d85
timestamp: 2016-01-18 14:35:56

Version Info:

0: [No Data]

Win32:Bandook-B [Trj] also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Razy.676886
McAfeeGenericRXAA-AA!0F7858BDAE11
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW32/LdPinch.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
BitDefenderGen:Variant.Razy.676886
AvastWin32:Bandook-B [Trj]
Ad-AwareGen:Variant.Razy.676886
EmsisoftGen:Variant.Razy.676886 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
FireEyeGeneric.mg.0f7858bdae11dcc3
SophosML/PE-A + Mal/Basine-C
IkarusTrojan.Patched
GDataGen:Variant.Razy.676886
AviraTR/Patched.Ren.Gen
ArcabitTrojan.Razy.DA5416
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R300580
Acronissuspicious
ALYacGen:Variant.Razy.676886
MAXmalware (ai score=89)
CylanceUnsafe
RisingBackdoor.Bandook!1.CFC8 (RDMK:cmRtazrDW66RkLarh0wDPIvm7/os)
YandexTrojan.Agent!l/d79G5ti2Y
SentinelOneStatic AI – Malicious PE
BitDefenderThetaGen:NN.ZexaF.34638.@pZ@aukh8Ud
AVGWin32:Bandook-B [Trj]

How to remove Win32:Bandook-B [Trj]?

Win32:Bandook-B [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment