Malware

Mal/Generic-R + Troj/Banker-GYO information

Malware Removal

The Mal/Generic-R + Troj/Banker-GYO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Banker-GYO virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Mal/Generic-R + Troj/Banker-GYO?


File Info:

name: 0CE2D7D9613213855E76.mlw
path: /opt/CAPEv2/storage/binaries/35d2bec1d2d0be9ef1119c8f5d761ee0ef38a31138277c934f464ccd84f7d791
crc32: 3CDF6C15
md5: 0ce2d7d9613213855e76d4ff74edc7be
sha1: 9707ee0ca5c6316843c3acbc793b8631b288190c
sha256: 35d2bec1d2d0be9ef1119c8f5d761ee0ef38a31138277c934f464ccd84f7d791
sha512: 6488649425880b640d67324dcd4491a73065f9eaa517b4652042faf6f8b0c5ceb7c733b3f432dabf46cdabbead8d14d3219accc51b781db1573836113179d791
ssdeep: 24576:ITyz5IxDVKzX8ezupcXOz6/XMe3rd14wY2kQf5l:ITbLK9rT8e3rd1pY2kIl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE255C3FB7899672C83209BC9E8FD2D598497A326E145947F7806F0C7E345A1372AE43
sha3_384: f7305f7d58f913ade1b6a1b3b54b97309f34922a9addb6260ff23b6da1a3fe4735df001365f2623e1ceec096e32d9410
ep_bytes: 558bec83c4f05356b878474e00e8c624
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: HP Printers
FileDescription: Utility printer driver
FileVersion: 1.0.0.52
InternalName:
LegalCopyright:
LegalTrademarks: HP Printers
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Translation: 0x0416 0x04e4

Mal/Generic-R + Troj/Banker-GYO also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Blocker.trVz
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Netmail-9844910-0
FireEyeGeneric.mg.0ce2d7d961321385
McAfeePWS-Banker.gen.ez
CylanceUnsafe
ZillyaTrojan.Agent.Win32.149212
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0026b47a1 )
BitDefenderGen:Variant.Doina.3244
K7GWSpyware ( 0026b47a1 )
Cybereasonmalicious.961321
BitDefenderThetaGen:NN.ZelphiF.34182.@G1@auNjbCjG
VirITTrojan.Win32.Banker5.COWW
CyrenW32/Banker.V.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Banker.WGA
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.kqig
AlibabaMalware:Win32/km_2e2d0ed.None
NANO-AntivirusTrojan.Win32.Agent.bskwly
ViRobotTrojan.Win32.A.Agent.1035264
MicroWorld-eScanGen:Variant.Doina.3244
AvastWin32:BankerX-gen [Trj]
TencentMalware.Win32.Gencirc.10b0d0bf
EmsisoftGen:Variant.Doina.3244 (B)
ComodoTrojWare.Win32.Spy.Banker.VIS@8ekceg
DrWebTrojan.MulDrop4.16500
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTrojanSpy.Win32.BANKER.SMTH
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.fh
SophosMal/Generic-R + Troj/Banker-GYO
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.ergo
AviraDR/Delphi.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.1B6D8
GridinsoftRansom.Win32.Banker.sa
MicrosoftTrojan:Win32/Dorv.B!rfn
ZoneAlarmTrojan-Ransom.Win32.Blocker.kqig
GDataWin32.Trojan-Stealer.Banker.AK
AhnLab-V3Trojan/Win32.Agent.C64982
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Doina.3244
TACHYONRansom/W32.DP-Blocker.1036276
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTrojanSpy.Win32.BANKER.SMTH
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Agent!xTHcMuXvyOs
IkarusTrojan-Banker.Win32.Delf
FortinetW32/Banker.WGA!tr
AVGWin32:BankerX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Mal/Generic-R + Troj/Banker-GYO?

Mal/Generic-R + Troj/Banker-GYO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment