Trojan

Trojan-Banker.Win32.Agent.aeih removal instruction

Malware Removal

The Trojan-Banker.Win32.Agent.aeih is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Agent.aeih virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Banker.Win32.Agent.aeih?


File Info:

name: 5DA510AB0DBF985397EA.mlw
path: /opt/CAPEv2/storage/binaries/fcd99fc47edef31f9a688dccc75ec65dc0a619fcb5a90db62239b3353ab5fcac
crc32: 518F924A
md5: 5da510ab0dbf985397eadd2ba1d3ef9c
sha1: 3688115a3478830094d1413794401cf30f276231
sha256: fcd99fc47edef31f9a688dccc75ec65dc0a619fcb5a90db62239b3353ab5fcac
sha512: a2159e2e39f3ad94364a51c464c5e1a567a44f8a0c6aab695555577a5a85eac7581f1d94936035eb3a158dca1d96ad9958dee42a2b623bdbb48e0a877f1169de
ssdeep: 24576:amoO8itDsZ8TdjFLb50uIfKyMgPr3kquu4OGKfvgjlxz:ROZ8jFLzoKaz3Nuu2KA5xz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A151202FBC68872D0325835491DE785A97CB5341F14CABFA7C94D5CAA701B1B236FA7
sha3_384: b6aa0520469b864c170c6bbb600b031f42336dc5f795f52ab9806b9a065147eab04051e82013da83e9ceed0121799665
ep_bytes: e88a040000e98efeffff3b0db8a14300
timestamp: 2017-08-11 13:54:06

Version Info:

0: [No Data]

Trojan-Banker.Win32.Agent.aeih also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.34581679
FireEyeTrojan.GenericKD.34581679
VIPRETrojan.GenericKD.34581679
K7AntiVirusTrojan ( 005239281 )
BitDefenderTrojan.GenericKD.34581679
K7GWTrojan ( 005239281 )
Cybereasonmalicious.b0dbf9
VirITTrojan.Win32.Banker.BIT
CyrenW32/ClipBanker.YYXG-1015
ESET-NOD32Win32/ClipBanker.CF
APEXMalicious
ClamAVWin.Dropper.DarkKomet-9304599-0
KasperskyTrojan-Banker.Win32.Agent.aeih
NANO-AntivirusTrojan.Win32.ClipBanker.ewvwmi
CynetMalicious (score: 99)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/ClipBanker.dtpfe
DrWebTrojan.ClipSpy.28
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.34581679 (B)
IkarusTrojan.Win32.Clipbanker
GDataTrojan.GenericKD.34581679
AviraTR/ClipBanker.dtpfe
Antiy-AVLTrojan/Win32.ClipBanker
ArcabitTrojan.Generic.D20FACAF
ZoneAlarmTrojan-Banker.Win32.Agent.aeih
MicrosoftTrojan:Win32/Ditertag.A
ALYacTrojan.GenericKD.34581679
MalwarebytesMalware.AI.216523737
PandaTrj/Genetic.gen
MAXmalware (ai score=87)
FortinetW32/ClipBanker.CF!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Trojan-Banker.Win32.Agent.aeih?

Trojan-Banker.Win32.Agent.aeih removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment