Trojan-Downloader:W32/Banload.FVQ, Trojan-Downloader.Win32.Agent.awqw, Downloader (Symantec)


This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files.


Automatic action

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

Find out more

Knowledge Base

Find the latest advice in our Community Knowledge Base.

User Guide

See the user guide for your product on the Help Center.

Contact Support

Chat with or call an expert for help.

Submit a sample

Submit a file or URL for further analysis.

Technical Details

This trojan is hosted on the website[...].php and executes automatically when the user visits the website. This trojan downloads a another trojan onto the system. The downloaded trojan steals the user's internet banking information and is detected as Trojan-Spy.Banbra.RM.


Upon execution, the trojan creates the file:

  • %temp%\bloloolol86.txt

This text file contains the text 'olha'.The trojan then downloads and execute the binary files:

  • %windir%\system32\innit226.exe
  • %windir%\system32\msnmsgsr.exe

To distract the user from detecting any malicious activity, the trojan also download innocuous-looking files from:


The first JPEG file, 001.jpg, will be renamed tomsnmsgsr.exe;the second JPEG file, 002.jpg, will be renamed toinnit226.exe. Both are renamed using Windows command prompt and stored on %windir%\system32. As these files share similar names with the malicious binary files, they help camouflage the trojan's activity.Upon successful execution of the trojan, Internet Explorer will open the page, a social networking site.This trojan was written in Borland Delphi.

Date Created: -

Date Last Modified: -