Threat Database Trojans Trojan.Banload.XG

Trojan.Banload.XG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,547
Threat Level: 80 % (High)
Infected Computers: 29
First Seen: December 4, 2024
Last Seen: July 23, 2026
OS(es) Affected: Windows

The detection of Trojan.Banload.XG on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating mechanisms, symptoms of infection, and steps to remove it from your system.

What Is Trojan.Banload.XG?

Trojan.Banload.XG is identified as a Trojan-type threat, which means it is a type of malware that disguises itself as legitimate software to gain unauthorized access to a computer system. The name itself does not directly indicate a specific malware family, but rather categorizes it under the broader umbrella of Trojan threats. Trojans are known for their ability to allow unauthorized access to the victim's system, potentially leading to data theft, system compromise, and further malware infections.

How Trojan.Banload.XG Operates

Like other Trojan threats, Trojan.Banload.XG is designed to operate stealthily, attempting to evade detection by security software. It may exploit vulnerabilities in software or use social engineering tactics to trick users into installing it. Once installed, it can create backdoors, allowing remote access to the system. This access can be used for a variety of malicious purposes, including data theft, installation of additional malware, or using the compromised system as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming.

Symptoms of Infection

Symptoms of a Trojan.Banload.XG infection can vary, but common indicators include unexpected system crashes, slow system performance, unusual network activity, and the appearance of unwanted programs or toolbars. Users may also notice that their system settings have been changed without their consent, or that they are being redirected to unwanted websites. Since Trojans can download and install other types of malware, the presence of Trojan.Banload.XG could lead to a wide range of additional symptoms associated with other malware types.

How to Remove Trojan.Banload.XG

  1. Enter Safe Mode with Networking: Restart your computer and enter Safe Mode with Networking. This will prevent non-essential programs from running, including the malware, and allow you to download and install removal tools if necessary.
  2. Perform a Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing Trojan.Banload.XG.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall anything that looks suspicious or unfamiliar. Be cautious, as some legitimate programs might be masquerading as malware, so proceed with caution.
  4. Reset Your Browser: If your browser has been affected, resetting it to its default settings can help remove unwanted extensions and settings changes. This can be done for browsers like Chrome, Firefox, and Edge through their respective settings menus.
  5. Reboot and Re-scan: After taking the above steps, reboot your system and perform another full scan with your anti-malware tool to ensure that all traces of the malware have been removed.

Conclusion

Removing Trojan.Banload.XG requires careful and systematic steps to ensure that all components of the malware are eliminated from the system. It's crucial to stay vigilant and maintain good cybersecurity practices to prevent future infections. Regularly updating your operating system, software, and security tools, along with being cautious when clicking on links or downloading attachments, can significantly reduce the risk of malware infections. If you're unsure about any part of the removal process, consider seeking help from a professional to ensure your system is thoroughly cleaned and protected.

Analysis Report

General information

Family Name: Trojan.Banload.XG
Packers: PECompact v2.20
Signature status: No Signature

Known Samples

MD5: 37163b01d6e3357a30c0ecb792678230
SHA1: 5fbff2933f70f1420761b5a4298d56a06a52fca5
SHA256: 4BAB98FC37BC5BC3A574B3B2C836890ABEFAEB4C384E68B0B1612DFAD91C79D1
File Size: 2.05 MB, 2050560 bytes
MD5: d954a290fc9a78b978eaafedb1a7c95b
SHA1: 5e0c9f259a45cef76fc9d970d5e64f7fc2420d47
SHA256: ACE8706F32827FC64C6ED0FD0FB5221A57871D0CE30085619111AE57EA000B93
File Size: 2.24 MB, 2242560 bytes
MD5: 564f946d0238aceb680209df32cf42ad
SHA1: a735d41f0156188ef26591e6d121ff0377c28dee
SHA256: C2C9980E46BC85C8410FD37B71E3CCADBE7025BD14168D6A044121430447DA3C
File Size: 1.73 MB, 1734144 bytes
MD5: e16566aed6edf7f275e993aedc8d74f0
SHA1: 9a3971f1be51845bf0bc9b5b5d1d242d860b0124
SHA256: EC7E4774EBEB55FEAE1C1EE68D7F1E9FF9BF235F67D51405B722A2467017B85A
File Size: 2.05 MB, 2054144 bytes
MD5: 2b944c96f71f6541a679e0bce7b03b5b
SHA1: 10841c05ea313146b547b092813d4320f37e267a
SHA256: 5250A1BADB6283CCAC66442CBBBF87D3190243B17517476A43DC839F39046EC8
File Size: 595.97 KB, 595968 bytes
Show More
MD5: a5ab5c8b80aa4f982cd1d434fa3b69b6
SHA1: 86fbf0acae7f19e3e0162a98b2a761d9bc8cbcf8
SHA256: D55FBFDB27FD056ED81CFA1A22F636F53EF8D6D4A2C473AB9EE20F3DB80F7E69
File Size: 506.37 KB, 506368 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsig Sistemas
File Version
  • 8.0.0.148
  • 8.0.0.131
  • 6.0.1.1
  • 1.4.0.0
  • 0.0.3.12
Legal Copyright Microsig Sistemas - Todos os direitos reservados.
Original Filename SAB.EXE
Product Name SAB - Sistema de Atualização de Banco
Product Version
  • v3.12
  • 22
  • 1.0.0.0

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • packed
  • PEC2
  • PECompact v2.20
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 2,931
Potentially Malicious Blocks: 2
Whitelisted Blocks: 2,922
Unknown Blocks: 7

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Caosoft.A
  • DllInject.FM
  • FakeAlert.E
  • Gamehack.BSB
  • HiLevel.A
Show More
  • Tibia.I

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 怴Ǭ䠱O噀ñ቎ĤÁŁ鱹9傄ë횎ǜ릣ʝ閾ʴ淃⟋ʪ柏ũߙĤᰂŁ鍂€ꩠŖÉ窵ň忶Ǥ RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Network Winsock2
  • WSAStartup