Spy

Should I remove “Spyware.Banker”?

Malware Removal

The Spyware.Banker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.Banker virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
dl.dropbox.com

How to determine Spyware.Banker?


File Info:

crc32: 5AFB05E9
md5: 3822edabe0dfea3950ace005eb2412ca
name: 3822EDABE0DFEA3950ACE005EB2412CA.mlw
sha1: 61fb0968edc184938e37e11600869d55b95c0d8a
sha256: d10cc371c64c8e009d9f71c82d24a6d77239bb6987fa66664794fde94858c6cd
sha512: ac8626e98e38d92c07a3a24023aba73d44f95a17b6e5a13fa418bf2d37e8e410fd8d2e349f8f15f237015b5fd780c79c3e006825888e591b5578948b4979c37a
ssdeep: 24576:CMs/5J2l6D5K3h/ZpWmQiNcGBXjg8uHQR7dq/qpRufGKflsteBUE9kc4ChEnh0:CLKtzNcEXjgFQ7CqioeZkKeh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Spyware.Banker also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader8.33716
MicroWorld-eScanTrojan.Delf.Inject.Z
FireEyeGeneric.mg.3822edabe0dfea39
CAT-QuickHealTrojan.Generic
ALYacTrojan.Delf.Inject.Z
MalwarebytesSpyware.Banker
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusSpyware ( 000644021 )
BitDefenderTrojan.Delf.Inject.Z
K7GWSpyware ( 000644021 )
Cybereasonmalicious.be0dfe
BitDefenderThetaAI:Packer.390D785421
CyrenW32/DelfInject.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Injector.QY
APEXMalicious
AvastWin32:Spyware-gen [Spy]
ClamAVWin.Trojan.Banker-7714
KasperskyHEUR:Trojan.Win32.Generic
AlibabaVirTool:Win32/DelfInject.fc1bd35f
TencentMalware.Win32.Gencirc.11492ba4
Ad-AwareTrojan.Delf.Inject.Z
SophosMal/Inject-DJ
ComodoMalware@#2waihjyhctzmy
F-SecureDropper.DR/Delphi.Gen
ZillyaTrojan.Pincav.Win32.18616
TrendMicroTROJ_GEN.R002C0CLL20
McAfee-GW-EditionGenericR-KHB!3822EDABE0DF
EmsisoftTrojan.Delf.Inject.Z (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Pincav.ozn
eGambitUnsafe.AI_Score_100%
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Win32.Pincav
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Delf.Inject.Z
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Pincav.R19455
McAfeeGenericR-KHB!3822EDABE0DF
VBA32Trojan.Pincav
PandaGeneric Malware
ESET-NOD32a variant of Win32/Spy.Banker.WTP
TrendMicro-HouseCallTROJ_GEN.R002C0CLL20
RisingSpyware.Banker!8.8D (TFE:5:q6iOKj9dAvF)
YandexTrojan.GenAsa!5OgDamDO+Wo
MAXmalware (ai score=80)
FortinetW32/Generic.AC.22D5AE!tr
AVGWin32:Spyware-gen [Spy]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM05.1.11F7.Malware.Gen

How to remove Spyware.Banker?

Spyware.Banker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment