We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
TrojanDownloader:Win32/Banload.AQV
Aliases: Win32/TrojanDownloader.Banload.RKH (ESET) Luhe.Fiha.P (AVG) Mal/VB-ABHH (Sophos) TROJ_SPNR.09AH13 (Trend Micro) Trojan.Banload!4DA8 (Rising AV) Trojan.BhoSiggen.7008 (Dr.Web) Trojan.Win32.BHO.ckak (Kaspersky) W32/Obfuscated.X!genr (Norman) Win-Trojan/Banload.35840.DW (AhnLab)
Summary
TrojanDownloader:Win32/Banload.AQV is a trojan that downloads and runs other malware from the Internet, sends information about your computer to a remote server, and modifies your computer's security settings.
You may be lured into opening the trojan, thinking it is a legitimate Microsoft Office file (for example, a Word document or Access database).
TrojanDownloader:Win32/Banload.AQV attempts to steal sensitive and confidential information from affected users to perpetrate fraud. If you believe that your personal financial information may have been compromised, please refer to the following advisory for additional advice:
The malware may steal your information by recording your usernames and passwords. After removal of the threat you should change your passwords. Please refer to the following advisory for tips on how to create and use passwords:
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
- Microsoft Security Essentials or, for Windows 8, Windows Defender
- Microsoft Safety Scanner
- Microsoft Windows Malicious Software Removal Tool
TrojanDownloader:Win32/Banload.AQV attempts to steal sensitive and confidential information from affected users to perpetrate fraud. If you believe that your personal financial information may have been compromised, please refer to the following advisory for additional advice:
The malware may steal your information by recording your usernames and passwords. After removal of the threat you should change your passwords. Please refer to the following advisory for tips on how to create and use passwords: