Trojan

What is “Trojan.Banker.Delf.AAGP”?

Malware Removal

The Trojan.Banker.Delf.AAGP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Banker.Delf.AAGP virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Banker.Delf.AAGP?


File Info:

name: 9B7F9ABE74871F3FB3D0.mlw
path: /opt/CAPEv2/storage/binaries/c8a76defb853d23ed85272608f26e9d73d4e906f835cabe5d950482e8087f0e1
crc32: 5A4E83AC
md5: 9b7f9abe74871f3fb3d079a55f17f1fc
sha1: 0a1103e73b169986dc683b48f3b5f7191f8624fe
sha256: c8a76defb853d23ed85272608f26e9d73d4e906f835cabe5d950482e8087f0e1
sha512: 08636cb75ac051bde0b1f19da2e83b0689ba9d6072ab1b5c3163c553151279cf89e80942754638d5e1ebe84d8a2fe8aab4c32c23d02c8cc28c76a5fa42ba9e9c
ssdeep: 49152:Nr1PJxSQR9sqVhL8taDqLS6M+ZDJZ0hkD/DwLFOd+0PHa7kn:t1tR9sq7eaF6RZDJZ0CzDSs+B7+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184B57D13B2C5543BD0761F3A8C6B97C4583F7A202F16B81B2EE42E4D0E39B416D7AA57
sha3_384: 4bf289c8d05c6cf795c33d85af1f8b64a261963086e2f1ae149c3fd56a6497fe9558e88d15f77bf496d2d03d02d4b6e0
ep_bytes: 558bec83c4f0b8a0345700e89ccfe8ff
timestamp: 2012-03-11 01:59:39

Version Info:

0: [No Data]

Trojan.Banker.Delf.AAGP also known as:

LionicTrojan.Win32.Bancos.7!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Banker.64539
MicroWorld-eScanTrojan.Banker.Delf.AAGP
FireEyeGeneric.mg.9b7f9abe74871f3f
McAfeeArtemis!9B7F9ABE7487
ZillyaTrojan.Bancos.Win32.11249
SangforTrojan.Win32.Bancos.atCCY
Cybereasonmalicious.e74871
CyrenW32/Trojan.LEOL-0114
SymantecTrojan.Gen.2
ESET-NOD32Win32/Spy.Banker.YPO
APEXMalicious
ClamAVWin.Trojan.Bancos-20400
KasperskyTrojan-Banker.Win32.Bancos.txb
BitDefenderTrojan.Banker.Delf.AAGP
SUPERAntiSpywareTrojan.Agent/Gen-Banker
AvastWin32:Bancos-CCY [Spy]
TencentMalware.Win32.Gencirc.114c1627
Ad-AwareTrojan.Banker.Delf.AAGP
EmsisoftTrojan.Banker.Delf.AAGP (B)
ComodoMalware@#155dc78rjl4z4
VIPRETrojan.Banker.Delf.AAGP
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Banker.Bancos.htp
WebrootW32.Malware.Gen
GoogleDetected
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.281
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Banker.Delf.AAGP
GDataTrojan.Banker.Delf.AAGP
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Banker.C158392
VBA32TrojanBanker.Bancos
ALYacTrojan.Banker.Delf.AAGP
RisingTrojan.Generic@AI.84 (RDML:EyM7bcEmM4qfruB8fT4NeA)
YandexTrojan.GenAsa!wq62QwVGobc
IkarusTrojan-Spy.Bancos
FortinetW32/Bancos.TXB!tr
AVGWin32:Bancos-CCY [Spy]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.Banker.Delf.AAGP?

Trojan.Banker.Delf.AAGP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment