Trojan

What is “Trojan-Banker.Win32.Bancos.okw”?

Malware Removal

The Trojan-Banker.Win32.Bancos.okw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Bancos.okw virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Banker.Win32.Bancos.okw?


File Info:

name: C01414EEB2D28E35C273.mlw
path: /opt/CAPEv2/storage/binaries/c62e87e7ad3a3e2576271eaef08b9f87723bca41730106a44339d46d50935a39
crc32: 2D5E0DF7
md5: c01414eeb2d28e35c273aeae30d16689
sha1: 34bbc9f3e9b382921df7a8bded6bdf9d380da803
sha256: c62e87e7ad3a3e2576271eaef08b9f87723bca41730106a44339d46d50935a39
sha512: 78b1113de23f432beedfc57b38fe2ed4f95fd413b0abfb251291d5626dbd008edb7d11c2b494d4fb2d70cdbc71be295c69444cb59106571517197015a0716e72
ssdeep: 1536:h1awvdckFDKfHrnrsuqPZtDXvr3aXFsQ2y8MXQpy9TY64:XawnF6iZJvrYs28ZEG6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AF839E14B6A00CF3D9A21E7456113737A37EE930283599AFDB744E8F5B648C2B12E787
sha3_384: 97c6e0ccccd0945019d7a927d1d08642c92a67a9409023433eebd96c4be38434116e0446e844b315fb06a9573ad733a0
ep_bytes: 558bec81ec40040000e8f5100000e877
timestamp: 2008-03-02 04:10:12

Version Info:

0: [No Data]

Trojan-Banker.Win32.Bancos.okw also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.UserStartup.fqW@aq8TCwj
FireEyeGeneric.mg.c01414eeb2d28e35
CAT-QuickHealTrojan.Generic.20707
McAfeePWS-Zbot.gen.ajl
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.6556
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 004da6c81 )
BitDefenderGen:Trojan.UserStartup.fqW@aq8TCwj
K7GWSpyware ( 004da6c81 )
Cybereasonmalicious.eb2d28
BitDefenderThetaAI:Packer.FC2568AF1E
CyrenW32/Agent.CC.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.Zbot.ACH
APEXMalicious
ClamAVWin.Spyware.Zbot-9841872-0
KasperskyTrojan-Banker.Win32.Bancos.okw
NANO-AntivirusTrojan.Win32.Panda.ifgd
CynetMalicious (score: 100)
RisingTrojan.Generic@AI.100 (RDML:Wdko2ZSvlDs4fs7rH+zQSg)
Ad-AwareGen:Trojan.UserStartup.fqW@aq8TCwj
SophosML/PE-A + Troj/Zbot-HJ
ComodoTrojWare.Win32.Spy.Zbot.ABW@1qnp50
DrWebTrojan.PWS.Panda.171
VIPREGen:Trojan.UserStartup.fqW@aq8TCwj
TrendMicroTSPY_ZBOT.SMRL
McAfee-GW-EditionPWS-Zbot.gen.ajl
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.UserStartup.fqW@aq8TCwj (B)
IkarusPWS.Win32
JiangminTrojanSpy.Zbot.xnx
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.31
MicrosoftPWS:Win32/Zbot.gen!R
GDataGen:Trojan.UserStartup.fqW@aq8TCwj
GoogleDetected
AhnLab-V3Win-Trojan/Zbot.Gen
VBA32SScope.Trojan.Bofa
ALYacGen:Trojan.UserStartup.fqW@aq8TCwj
MAXmalware (ai score=83)
MalwarebytesMalware.AI.2980580767
TrendMicro-HouseCallTSPY_ZBOT.SMRL
SentinelOneStatic AI – Malicious PE
FortinetW32/Zbot.BCW!tr.bdr
AVGSf:Zbot-CQ [Trj]
AvastSf:Zbot-CQ [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan-Banker.Win32.Bancos.okw?

Trojan-Banker.Win32.Bancos.okw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment