Trojan

Trojan-Banker.Win32.NeutrinoPOS.eey information

Malware Removal

The Trojan-Banker.Win32.NeutrinoPOS.eey is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.NeutrinoPOS.eey virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Hebrew
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
a.dnspod.com
nomoreransom.bit
bleepingcomputer.bit
emsisoft.bit
esetnod32.bit
gandcrab.bit

How to determine Trojan-Banker.Win32.NeutrinoPOS.eey?


File Info:

crc32: 21D8C7FE
md5: d32d05e568bd76383c888d562a99fd6d
name: D32D05E568BD76383C888D562A99FD6D.mlw
sha1: f99bdb0a406683a52bafbcf052dd3dee4a98e6ad
sha256: 9693c8ccb86e642135dd8c0f52aece94be3dcce17a02eaff89fbd0b9410d7f6d
sha512: f48bd02be39fa0db01e5d94e6bf98e6113bca38035819b1d2e3226b278b94cd593e1c4acea427764424db1ccdc6e1cb0554b974611c404f7b8d079a2424c7df9
ssdeep: 3072:zNYyI9ogb8eovM3DNan+MJHoyNxHGS/p6ux:zvO8eoE++clHGQ6u
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, phpdummiess
FileVersion: 6.3.6.8
ProductVersion: 6.3.6.8
Translation: 0x0809 0x04b0

Trojan-Banker.Win32.NeutrinoPOS.eey also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad4.931
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacTrojan.BRMon.Gen.3
MalwarebytesRansom.GandCrab
ZillyaTrojan.NeutrinoPOS.Win32.81
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.568bd7
CyrenW32/S-dea5fd14!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GCPG
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Generic-9853074-1
KasperskyTrojan-Banker.Win32.NeutrinoPOS.eey
BitDefenderTrojan.BRMon.Gen.3
NANO-AntivirusTrojan.Win32.NeutrinoPOS.exlshm
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanTrojan.BRMon.Gen.3
TencentTrojan.Win32.Gandcrypt.b
Ad-AwareTrojan.BRMon.Gen.3
SophosMal/Generic-R + Mal/Kryptik-BL
ComodoApplication.Win32.IStartSurf.PS@8c4m91
BitDefenderThetaGen:NN.ZexaF.34684.ju0@ae84pvqG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMONT
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.d32d05e568bd7638
EmsisoftTrojan.BRMon.Gen.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.NeutrinoPOS.bw
AviraHEUR/AGEN.1117310
eGambitUnsafe.AI_Score_99%
AegisLabTrojan.Win32.NeutrinoPOS.tpgC
GDataTrojan.BRMon.Gen.3
TACHYONBanker/W32.NeutrinoPOS.149504
AhnLab-V3Trojan/Win.MalPe.X2055
Acronissuspicious
McAfeePacked-ZG!D32D05E568BD
MAXmalware (ai score=98)
VBA32BScope.Trojan.Suloc
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMONT
RisingRansom.GandCrab!1.B152 (RDMK:cmRtazqrb8DQ2R6UvlLC7RCjw83t)
YandexTrojan.GenAsa!q1Y64ZBrNgw
IkarusTrojan.Crypt
MaxSecureRansomeware.CRAB.gen
FortinetW32/GenKryptik.CPZI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.NeutrinoPOS.eey?

Trojan-Banker.Win32.NeutrinoPOS.eey removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment