Trojan

Trojan.Banker.WHS (file analysis)

Malware Removal

The Trojan.Banker.WHS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Banker.WHS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Network activity detected but not expressed in API logs

How to determine Trojan.Banker.WHS?


File Info:

crc32: 76E17F09
md5: 3e85b359534eb4df57bb77524eb67b30
name: 3E85B359534EB4DF57BB77524EB67B30.mlw
sha1: 195dab6303b7a0bec2a1135071483a8da2a048b8
sha256: a034ce8ff996aff2cbeb49442a38fc298b9dad5964040ef0c4f4e659c0744689
sha512: bf04feb6eb978aaf2138526e0be028fa5a10fb13f1deabd6887a52eebba6920e7aaec5639ebbdd4607f12a8c93eb96750702bd0bf53a3f11915a965a273bc8f3
ssdeep: 768:da4dWqkOqltuUkltJ3R0lMdjxqJI0HRHz/sNTcFGlfZL:k44q2tuUkl7h0CdjxII0mcFGJZL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: a318be1f102c40d386d2ea47f3554004
Assembly Version: 1.0.0.0
InternalName: KLFINAL42433.exe
FileVersion: 1.0.0.0
ProductName: a318be1f102c40d386d2ea47f3554004
ProductVersion: 1.0.0.0
FileDescription: a318be1f102c40d386d2ea47f3554004
OriginalFilename: KLFINAL42433.exe

Trojan.Banker.WHS also known as:

K7AntiVirusPassword-Stealer ( 0055e3ee1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader12.54223
CAT-QuickHealTrojan.GenericFC.S6060297
ALYacTrojan.GenericKDZ.72429
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.31657
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:MSIL/Blocker.d1cd710a
K7GWPassword-Stealer ( 0055e3ee1 )
Cybereasonmalicious.9534eb
CyrenW32/MSIL_Agent.BSC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.Agent.PDK
APEXMalicious
AvastWin32:Broban-AQ [Trj]
ClamAVWin.Packed.Banload-9785270-0
KasperskyTrojan-Ransom.Win32.Blocker.gsyt
BitDefenderTrojan.GenericKDZ.72429
NANO-AntivirusTrojan.Win32.Blocker.dpmkkx
MicroWorld-eScanTrojan.GenericKDZ.72429
TencentMalware.Win32.Gencirc.10ce3207
Ad-AwareTrojan.GenericKDZ.72429
SophosMal/Generic-R + Troj/MSILDrop-E
ComodoMalware@#165k8ls00pfz7
BitDefenderThetaGen:NN.ZemsilF.34690.cq0@ae7Vw5b
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_BANLOAD.YWNFS
McAfee-GW-EditionPWS-FCBK!3E85B359534E
FireEyeGeneric.mg.3e85b359534eb4df
EmsisoftTrojan.GenericKDZ.72429 (B)
JiangminTrojan.Blocker.cn
AviraHEUR/AGEN.1101148
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.F6C220
MicrosoftTrojanSpy:MSIL/Banker.M
AegisLabTrojan.Win32.Blocker.j!c
GDataMSIL.Trojan.Escelar.A
AhnLab-V3Trojan/Win32.Limitail.R141206
McAfeePWS-FCBK!3E85B359534E
MAXmalware (ai score=100)
VBA32Hoax.Blocker
MalwarebytesTrojan.Banker.WHS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_BANLOAD.YWNFS
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!raLEjDEU5zU
IkarusTrojan-Downloader.MSIL.Banload
FortinetMSIL/Agent.PDK!tr.pws
AVGWin32:Broban-AQ [Trj]
Paloaltogeneric.ml

How to remove Trojan.Banker.WHS?

Trojan.Banker.WHS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment