Trojan

Trojan.Banker.VB.BED removal guide

Malware Removal

The Trojan.Banker.VB.BED is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Banker.VB.BED virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Banker.VB.BED?


File Info:

name: 37723DB449C5DAF08213.mlw
path: /opt/CAPEv2/storage/binaries/e5b8b61d87264a35e054eb795a16836634bf98df8c13caee47eb0355bd457e6c
crc32: 406BF4C1
md5: 37723db449c5daf082130e004f82ae94
sha1: 5df567a6bbc211f6169848c747ba1c4ebe47ba10
sha256: e5b8b61d87264a35e054eb795a16836634bf98df8c13caee47eb0355bd457e6c
sha512: 8bba81c426baeeefebc8c88ad376ba13964f7a9a71c6135a9b49e8c3e7084bdc8db9213f88f905302ad4a5822b80950f69eba68bfd720df490824189376fe948
ssdeep: 1536:O7Ew7ICWDnLwZBk1FYKg99oFWZBYSkCXrbnouy8wZvcEZbla4:aEf5DnEZBkPY59OkZPkCXrDoutwZUov
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB93E042B444CB67F28D8D3D706B9BA849363CA0AA71E7EB35C0325BDD7B7401A2D953
sha3_384: 02671160ccc44095ebff4252543efb7292de4a905e8e8ae4193a5b84972a0e8a7f3634687ff4637e15f0e65263174060
ep_bytes: 60be001042008dbe0000feff5789e58d
timestamp: 2008-05-24 04:36:37

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Home
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: loader
OriginalFilename: loader.scr

Trojan.Banker.VB.BED also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VB.lALS
tehtrisGeneric.Malware
DrWebTrojan.DownLoader1.9118
MicroWorld-eScanTrojan.Banker.VB.BED
FireEyeGeneric.mg.37723db449c5daf0
SkyhighBehavesLike.Win32.Generic.nc
McAfeeGenericRXAA-AA!37723DB449C5
Cylanceunsafe
ZillyaDownloader.Banload.Win32.26434
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0000000c1 )
AlibabaTrojanDownloader:Win32/Banload.cf57045e
K7GWTrojan ( 0000000c1 )
ArcabitTrojan.Banker.VB.BED
BitDefenderThetaAI:Packer.60B814DD1D
SymantecDownloader
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.PZS
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.38574-1
KasperskyVHO:Trojan.Win32.GenericML.xnet
BitDefenderTrojan.Banker.VB.BED
NANO-AntivirusTrojan.Win32.Banload.uacn
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan.Dropper.Rsmw
EmsisoftTrojan.Banker.VB.BED (B)
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.Banker.VB.BED
TrendMicroMal_Banker15
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
VaristW32/VBTrojan.17D1!Maximus
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Downloader]/Win32.Banload
KingsoftWin32.HeurC.KVM007.a
XcitiumMalware@#11v0svmpyifsx
MicrosoftTrojan:Win32/DSSDetection
ZoneAlarmVHO:Trojan.Win32.GenericML.xnet
GDataTrojan.Banker.VB.BED
GoogleDetected
AhnLab-V3Trojan/Win32.Banload.C50671
VBA32BScope.Trojan.Schoolboy
ALYacTrojan.Banker.VB.BED
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Nabload.ACN
TrendMicro-HouseCallMal_Banker15
RisingTrojan.Win32.Generic.13B55C44 (C64:YzY0OjTy4ZM4C7FP)
YandexTrojan.DL.Banload!PdMV5dwF8cM
IkarusTrojan-Banker.Win32.Bancos
MaxSecureTrojan.Malware.743028.susgen
FortinetW32/Generic.AC.1F8818!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Banker.VB.BED?

Trojan.Banker.VB.BED removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment