Trojan.Banload.XG
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 13,547 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 29 |
| First Seen: | December 4, 2024 |
| Last Seen: | July 23, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Banload.XG on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating mechanisms, symptoms of infection, and steps to remove it from your system.
Table of Contents
What Is Trojan.Banload.XG?
Trojan.Banload.XG is identified as a Trojan-type threat, which means it is a type of malware that disguises itself as legitimate software to gain unauthorized access to a computer system. The name itself does not directly indicate a specific malware family, but rather categorizes it under the broader umbrella of Trojan threats. Trojans are known for their ability to allow unauthorized access to the victim's system, potentially leading to data theft, system compromise, and further malware infections.
How Trojan.Banload.XG Operates
Like other Trojan threats, Trojan.Banload.XG is designed to operate stealthily, attempting to evade detection by security software. It may exploit vulnerabilities in software or use social engineering tactics to trick users into installing it. Once installed, it can create backdoors, allowing remote access to the system. This access can be used for a variety of malicious purposes, including data theft, installation of additional malware, or using the compromised system as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming.
Symptoms of Infection
Symptoms of a Trojan.Banload.XG infection can vary, but common indicators include unexpected system crashes, slow system performance, unusual network activity, and the appearance of unwanted programs or toolbars. Users may also notice that their system settings have been changed without their consent, or that they are being redirected to unwanted websites. Since Trojans can download and install other types of malware, the presence of Trojan.Banload.XG could lead to a wide range of additional symptoms associated with other malware types.
How to Remove Trojan.Banload.XG
- Enter Safe Mode with Networking: Restart your computer and enter Safe Mode with Networking. This will prevent non-essential programs from running, including the malware, and allow you to download and install removal tools if necessary.
- Perform a Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing Trojan.Banload.XG.
- Uninstall Suspicious Programs: Go through your installed programs and uninstall anything that looks suspicious or unfamiliar. Be cautious, as some legitimate programs might be masquerading as malware, so proceed with caution.
- Reset Your Browser: If your browser has been affected, resetting it to its default settings can help remove unwanted extensions and settings changes. This can be done for browsers like Chrome, Firefox, and Edge through their respective settings menus.
- Reboot and Re-scan: After taking the above steps, reboot your system and perform another full scan with your anti-malware tool to ensure that all traces of the malware have been removed.
Conclusion
Removing Trojan.Banload.XG requires careful and systematic steps to ensure that all components of the malware are eliminated from the system. It's crucial to stay vigilant and maintain good cybersecurity practices to prevent future infections. Regularly updating your operating system, software, and security tools, along with being cautious when clicking on links or downloading attachments, can significantly reduce the risk of malware infections. If you're unsure about any part of the removal process, consider seeking help from a professional to ensure your system is thoroughly cleaned and protected.
Analysis Report
General information
| Family Name: | Trojan.Banload.XG |
|---|---|
| Packers: | PECompact v2.20 |
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
37163b01d6e3357a30c0ecb792678230
SHA1:
5fbff2933f70f1420761b5a4298d56a06a52fca5
SHA256:
4BAB98FC37BC5BC3A574B3B2C836890ABEFAEB4C384E68B0B1612DFAD91C79D1
File Size:
2.05 MB, 2050560 bytes
|
|
MD5:
d954a290fc9a78b978eaafedb1a7c95b
SHA1:
5e0c9f259a45cef76fc9d970d5e64f7fc2420d47
SHA256:
ACE8706F32827FC64C6ED0FD0FB5221A57871D0CE30085619111AE57EA000B93
File Size:
2.24 MB, 2242560 bytes
|
|
MD5:
564f946d0238aceb680209df32cf42ad
SHA1:
a735d41f0156188ef26591e6d121ff0377c28dee
SHA256:
C2C9980E46BC85C8410FD37B71E3CCADBE7025BD14168D6A044121430447DA3C
File Size:
1.73 MB, 1734144 bytes
|
|
MD5:
e16566aed6edf7f275e993aedc8d74f0
SHA1:
9a3971f1be51845bf0bc9b5b5d1d242d860b0124
SHA256:
EC7E4774EBEB55FEAE1C1EE68D7F1E9FF9BF235F67D51405B722A2467017B85A
File Size:
2.05 MB, 2054144 bytes
|
|
MD5:
2b944c96f71f6541a679e0bce7b03b5b
SHA1:
10841c05ea313146b547b092813d4320f37e267a
SHA256:
5250A1BADB6283CCAC66442CBBBF87D3190243B17517476A43DC839F39046EC8
File Size:
595.97 KB, 595968 bytes
|
Show More
|
MD5:
a5ab5c8b80aa4f982cd1d434fa3b69b6
SHA1:
86fbf0acae7f19e3e0162a98b2a761d9bc8cbcf8
SHA256:
D55FBFDB27FD056ED81CFA1A22F636F53EF8D6D4A2C473AB9EE20F3DB80F7E69
File Size:
506.37 KB, 506368 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has been packed
- File has TLS information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | Microsig Sistemas |
| File Version |
|
| Legal Copyright | Microsig Sistemas - Todos os direitos reservados. |
| Original Filename | SAB.EXE |
| Product Name | SAB - Sistema de Atualização de Banco |
| Product Version |
|
File Traits
- 2+ executable sections
- HighEntropy
- No Version Info
- packed
- PEC2
- PECompact v2.20
- WriteProcessMemory
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 2,931 |
|---|---|
| Potentially Malicious Blocks: | 2 |
| Whitelisted Blocks: | 2,922 |
| Unknown Blocks: | 7 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Caosoft.A
- DllInject.FM
- FakeAlert.E
- Gamehack.BSB
- HiLevel.A
Show More
- Tibia.I
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | 怴 Ǭ䠱O噀ñĤÁŁ鱹9傄ë횎ǜ릣ʝ閾ʴ淃⟋ʪ柏ũߙĤ ᰂŁ鍂ꩠŖÉ窵ň忶Ǥ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| User Data Access |
|
| Network Winsock2 |
|