Trojan

How to remove “Dropped:Trojan.Banker.VB.AB”?

Malware Removal

The Dropped:Trojan.Banker.VB.AB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.Banker.VB.AB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Dropped:Trojan.Banker.VB.AB?


File Info:

crc32: 4713237E
md5: 6e9802ad5331e7d8e643de8b114b8b66
name: 6E9802AD5331E7D8E643DE8B114B8B66.mlw
sha1: 32978b13e40bee227a3b9f82a1a34913e112eafe
sha256: 98c5f82c61c527d435526899cf31d94fadeafbe57a7aa12992c0923d84f3be6f
sha512: dbd43a6705fe8e0907ef2d504c96bc53a981287150832f512a60c9245c87fac931d829e8374ccbba824b2073d137db63db964b37c343763e10421d149bc266b5
ssdeep: 3072:rhj5GS8af+CMIFdSE8peoU5SSKJfyLL9+ZAtGa:djwK+CndCo95SSGfyLL9n7
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Microsoft Corporation
InternalName: kernelsNT
FileVersion: 3.00
CompanyName: Microsoft Corporation
LegalTrademarks: Microsoft Corporation
Comments: kernelNT
ProductName: kernelNT
ProductVersion: 3.00
FileDescription: kernelNT.exe
OriginalFilename: kernelsNT.exe

Dropped:Trojan.Banker.VB.AB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005376ae1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Bancos.207
CynetMalicious (score: 100)
ALYacDropped:Trojan.Banker.VB.AB
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.d5331e
BaiduWin32.Trojan.Bancos.a
CyrenW32/Bancos.AJWK-3013
SymantecInfostealer.Bancos
ESET-NOD32Win32/Spy.Bancos.U
APEXMalicious
AvastWin32:Bancos-IK [Trj]
ClamAVWin.Spyware.Banker-663
KasperskyTrojan-Banker.Win32.Bancos.ha
BitDefenderDropped:Trojan.Banker.VB.AB
NANO-AntivirusTrojan.Win32.Banker.eprp
MicroWorld-eScanDropped:Trojan.Banker.VB.AB
TencentMalware.Win32.Gencirc.10b5475f
Ad-AwareDropped:Trojan.Banker.VB.AB
SophosML/PE-A + Troj/Bancos-RO
ComodoTrojWare.Win32.Spy.Bancos.U@3ais
BitDefenderThetaGen:NN.ZevbaF.34686.hi0fa0y1aqoi
VIPRETrojan-Spy.Win32.Bancos.ha (v)
TrendMicroTSPY_BANKER.ATB
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
FireEyeGeneric.mg.6e9802ad5331e7d8
EmsisoftDropped:Trojan.Banker.VB.AB (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanSpy.Bancos.ay
AviraTR/Spy.Bancos.PQ
MicrosoftTrojanSpy:Win32/Bancos
ZoneAlarmTrojan-Banker.Win32.Bancos.ha
GDataDropped:Trojan.Banker.VB.AB
AhnLab-V3Trojan/Win32.Bancos.C23702
Acronissuspicious
McAfeePWS-Banker.gen.h
MAXmalware (ai score=82)
VBA32SIM.Trojan.VBO.0577
PandaTrj/Banker.ANL
TrendMicro-HouseCallTSPY_BANKER.ATB
RisingTrojan.Bancos!1.98E3 (CLOUD)
YandexTrojan.PWS.Bancos!bwUfpiQ3Vp8
IkarusTrojan-Banker.Win32.Bancos
MaxSecureTrojan.bancos.ha
FortinetW32/Bancos.HA!tr
AVGWin32:Bancos-IK [Trj]
Paloaltogeneric.ml

How to remove Dropped:Trojan.Banker.VB.AB?

Dropped:Trojan.Banker.VB.AB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment