Malware

About “Banker.16” infection

Malware Removal

The Banker.16 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Banker.16 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: lel.exe
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Banker.16?


File Info:

crc32: EC2A0C8B
md5: 1d9c8cb7c258753d1704ae1c6ad6da26
name: lel.exe
sha1: 604e874610eab59a2f8b01d0bae5cc1800e14bfa
sha256: 283e573a7e0a235c97cebda171bf702bc5495fd287f0b17447f5ee78ab1ada33
sha512: 1870c8360038a40dcbb82e9fdd40e1b220b4f1ab9b7c0cefac80393689a6e2f3259bf8d38fdd722c631e7e9fdc165f24b4371686f701bed347f0abc7fc00b9b0
ssdeep: 49152:nv2qcVRKW5grSkF+dUKXEvqpwEkuF1gnLtbc9v6X2pLM39j:v2qeKW5cAUHbEb18tg9v6X2pYtj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Counter Strike : Global Offensive Hack
InternalName: Injetor de .dll
FileVersion: 0.0.0.1
CompanyName: Counter Strike : Global Offensive
LegalTrademarks:
Comments:
ProductName: Counter Strike : Global Offensive Injetor
ProductVersion: 0.0.0.1
FileDescription: Injetor de .dll
OriginalFilename: Counter Strike : Global Offensive Injetor
Translation: 0x0416 0x04e4

Banker.16 also known as:

BkavW32.HfsAutoB.
MicroWorld-eScanGen:Variant.Banker.16
CAT-QuickHealTrojan.IGENERIC
ALYacGen:Variant.Banker.16
CylanceUnsafe
K7AntiVirusTrojan ( 0040f4ef1 )
BitDefenderGen:Variant.Banker.16
K7GWTrojan ( 0040f4ef1 )
Cybereasonmalicious.7c2587
Invinceaheuristic
NANO-AntivirusTrojan.Win32.Phpw.ewmiag
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0WHS18
Paloaltogeneric.ml
GDataGen:Variant.Banker.16
KasperskyTrojan-Spy.MSIL.Phpw.q
AvastWin32:Malware-gen
TencentPhp.Trojan-spy.Phpw.Ebhs
Ad-AwareGen:Variant.Banker.16
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WHS18
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
EmsisoftGen:Variant.Banker.16 (B)
SentinelOnestatic engine – malicious
CyrenW32/Trojan.TGLO-3566
JiangminTrojanSpy.MSIL.ynh
WebrootPua.Hax
AviraTR/Spy.Banker.eibby
Antiy-AVLTrojan/Win32.TSGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Banker.16
AegisLabGen.Variant.Banker!c
ZoneAlarmTrojan-Spy.MSIL.Phpw.q
McAfeeArtemis!1D9C8CB7C258
AVwareTrojan.Win32.Generic!BT
MAXmalware (ai score=98)
VBA32TScope.Trojan.Delf
YandexTrojanSpy.Phpw!
IkarusTrojan-Spy.Agent
FortinetPossibleThreat
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikemalicious_confidence_100% (W)
Qihoo-360Win32/Trojan.87e

How to remove Banker.16?

Banker.16 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment