Trojan

What is “Trojan-Banker.Win32.Banker.xbrds”?

Malware Removal

The Trojan-Banker.Win32.Banker.xbrds is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Banker.xbrds virus can do?

  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
www.lunnevad.se
a.tomx.xyz

How to determine Trojan-Banker.Win32.Banker.xbrds?


File Info:

crc32: 179E2FD9
md5: 9e1f53418631c2b76144dbe3eeb09c5b
name: 9E1F53418631C2B76144DBE3EEB09C5B.mlw
sha1: 67de490eb6d5ee73c4741182a4201ad4c02eed1a
sha256: 2cb09fa0a10d40621aa0c71782d01123feaae215c6f87f2831577d9a19b19357
sha512: 52eb0799e9e12634716c8ba755224427c9d86428311d6d19b00e3bda6c08370a3c2c4ed49f90896432616875385c523d0e151a26d0e868ba92d14c7997be5c7c
ssdeep: 24576:8oWUVuqgGQguJdjjIfW5Q1s0sxBWYI5TlVVXDUmbW1v:BWY3uXOsHWXTDVQmbW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.Banker.xbrds also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 7000000f1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Banker1.20427
CynetMalicious (score: 100)
ALYacTrojan.Spy.Banker.ACQE
CylanceUnsafe
ZillyaTrojan.Banker.Win32.98579
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.18631c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Banker.ULI
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Banker.Win32.Banker.xbrds
BitDefenderTrojan.Spy.Banker.ACQE
NANO-AntivirusTrojan.Win32.Hexzone.bnlpc
MicroWorld-eScanTrojan.Spy.Banker.ACQE
TencentWin32.Trojan-banker.Banker.Hufv
Ad-AwareTrojan.Spy.Banker.ACQE
SophosMal/Bancos-M
ComodoMalware@#2bkpp9mt6wa14
BitDefenderThetaGen:NN.ZelphiF.34170.hHW@aC!tCunG
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroMal_Banker13
McAfee-GW-EditionPWS-Banker!gtx
FireEyeGeneric.mg.9e1f53418631c2b7
EmsisoftTrojan.Spy.Banker.ACQE (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Hexzone.aqb
AviraHEUR/AGEN.1128271
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.A3ABD5
MicrosoftTrojanSpy:Win32/Banker
GDataTrojan.Spy.Banker.ACQE
Acronissuspicious
McAfeePWS-Banker!gtx
MAXmalware (ai score=84)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.932774336
PandaTrj/CI.A
TrendMicro-HouseCallMal_Banker13
RisingTrojan.Generic@ML.95 (RDML:S8L2d0n9JNb+8clwK/Ogjw)
YandexTrojan.GenAsa!a2LnNNKoqQw
IkarusTrojan-Ransom.Hexzone
FortinetW32/Generic.AC.20836A!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.Banker.xbrds?

Trojan-Banker.Win32.Banker.xbrds removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment