Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Jan 22, 2013 | Updated Sep 15, 2017

TrojanDownloader:Win32/Banload.ARG

Detected by Microsoft Defender Antivirus

Aliases: BAT/Spy.Banker.AN (ESET) Trojan.DownLoader7.56719 (Dr.Web) Trojan-Banker.BAT.Qhost (Ikarus) BAT/ProxyChanger.dropper (AVG)

Summary

TrojanDownloader:Win32/Banload.ARG is a trojan that redirects your web browser so that when you attempt to access certain websites you are redirected to malicious sites that attempt to steal or "phish" your information.

This malware attempts to steal sensitive and confidential information from affected users to perpetrate fraud. If you believe that your personal financial information may have been compromised, please refer to the following advisory for additional advice:

The malware may steal your information by recording your usernames and passwords. After removal of the threat you should change your passwords. Please refer to the following advisory for tips on how to create and use passwords:

To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:

TrojanDownloader:Win32/Banload.ARG attempts to steal sensitive and confidential information from affected users to perpetrate fraud. If you believe that your personal financial information may have been compromised, please refer to the following advisory for additional advice:

The malware may steal your information by recording your usernames and passwords. After removal of the threat you should change your passwords. Please refer to the following advisory for tips on how to create and use passwords:

Additional remediation instructions for TrojanDownloader:Win32/Banload.ARG

This threat may make lasting changes to a computer's configuration that are not restored by detecting and removing this threat. For more information on returning an infected computer to its pre-infected state, please see the following articles:

Follow us