Trojan

About “Trojan-Banker.Win32.NeutrinoPOS.aye” infection

Malware Removal

The Trojan-Banker.Win32.NeutrinoPOS.aye is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.NeutrinoPOS.aye virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.NeutrinoPOS.aye?


File Info:

crc32: 05E47FE5
md5: 0db86a88d5c7ff11a5e75579fa3c5f3c
name: 0DB86A88D5C7FF11A5E75579FA3C5F3C.mlw
sha1: 445704917e7ab0fc0778bac66bf364c04826bf98
sha256: 804200fec1b1d52c0808afd15806382ad8395895a71fec623b2abb972164d87a
sha512: 3681f1e73c7c2cdc57d8d0936fb492412b286f144f7fc9fc16ad3b5bb3501776df321efeba3cc57c451e41c67318d6982c5fdc02b803e45b54d644873f7aa3c7
ssdeep: 3072:lVc7FbxmIt7WH4GMcYNIKAqY2yzfPJ/yMF5MNsploGVid5:7I904ogAR221BMGT4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.NeutrinoPOS.aye also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ6
ALYacTrojan.BRMon.Gen.3
CylanceUnsafe
ZillyaTrojan.NeutrinoPOS.Win32.333
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.8d5c7f
CyrenW32/S-c5d37cab!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GCQO
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packer.Crypter-6539596-1
KasperskyTrojan-Banker.Win32.NeutrinoPOS.aye
BitDefenderTrojan.BRMon.Gen.3
NANO-AntivirusTrojan.Win32.Deshacop.exmiod
ViRobotTrojan.Win32.Ransom.171520.E
SUPERAntiSpywareRansom.GandCrab/Variant
MicroWorld-eScanTrojan.BRMon.Gen.3
TencentMalware.Win32.Gencirc.10b49224
Ad-AwareTrojan.BRMon.Gen.3
SophosMal/Generic-R + Mal/Ransom-FN
ComodoApplication.Win32.IStartSurf.PS@8c4m91
BitDefenderThetaGen:NN.ZexaF.34628.kuW@aKnGYmb
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMONT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.0db86a88d5c7ff11
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.NeutrinoPOS.ca
AviraHEUR/AGEN.1117310
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Gandcrab.GM!MTB
AegisLabTrojan.Win32.Androm.tpgB
GDataTrojan.BRMon.Gen.3
TACHYONBanker/W32.NeutrinoPOS.171520
AhnLab-V3Trojan/Win.MalPe.X2055
Acronissuspicious
McAfeePacked-ZG!0DB86A88D5C7
MAXmalware (ai score=99)
VBA32Trojan.Miner
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMONT
RisingRansom.GandCrab!1.B152 (CLOUD)
YandexTrojan.PWS.NeutrinoPOS!5V3VSTBLC6g
IkarusTrojan-Dropper.Win32.Danabot
FortinetW32/GenKryptik.CPYR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoC5PcA

How to remove Trojan-Banker.Win32.NeutrinoPOS.aye?

Trojan-Banker.Win32.NeutrinoPOS.aye removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment