Trojan

Trojan-Banker.Win32.Trickster.evk removal tips

Malware Removal

The Trojan-Banker.Win32.Trickster.evk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Trickster.evk virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Collects and encrypts information about the computer likely to send to C2 server
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a copy of itself
  • Attempts to disable Windows Defender
  • Attempts to modify Windows Defender using PowerShell
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Banker.Win32.Trickster.evk?


File Info:

name: D5EF0CE4C5F4B5BC363E.mlw
path: /opt/CAPEv2/storage/binaries/026f3ecc27ae1e24fadf7f4bb0fb634d7f93e112fc6772daded926a0804892d6
crc32: F0B55676
md5: d5ef0ce4c5f4b5bc363ecc8577fcd678
sha1: f1e4a08542ec71d8faaed11c58c9e92e1451dfde
sha256: 026f3ecc27ae1e24fadf7f4bb0fb634d7f93e112fc6772daded926a0804892d6
sha512: cdc80216e324a1c2cb3eacd1b335a00befc6e3ccad6bd188ec9026b3bd218ac0d68ee3b38c1af742d15544d1f9bb3735edf132c5e9ec32b007199037ca395db6
ssdeep: 6144:l+viZjDJU9UgICxV08AuFZqup34w4vSwuDdc3syrffYBuBNmOdTSIpvVAjiv/58w:l18DVxhFZTF4w46wkc+jOWHuU4Cm12U7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12CA4E1A9FF864CE7DD25037484EBD31A433EF6E09A234F539A5458360E637E1AED4206
sha3_384: 0183a2a9ecd2f9c6428f269e5da76e8b414dce45c7fdc9d4520f0550818b78b023305be9af8498a4e01a3d863f6b213d
ep_bytes: 5589e583ec18c7042402000000ff151c
timestamp: 2019-03-18 09:35:14

Version Info:

0: [No Data]

Trojan-Banker.Win32.Trickster.evk also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.TrickBot.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Trickster.Gen
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054e0a71 )
AlibabaTrojanBanker:Win32/Trickster.6671cebf
K7GWTrojan ( 0054e0a71 )
Cybereasonmalicious.4c5f4b
CyrenW32/Trickbot.AL.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GQTG
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Trickbot-6919578-0
KasperskyTrojan-Banker.Win32.Trickster.evk
BitDefenderTrojan.Agent.DRVH
NANO-AntivirusTrojan.Win32.Trick.foeigt
MicroWorld-eScanTrojan.Agent.DRVH
TencentMalware.Win32.Gencirc.10b0e103
Ad-AwareTrojan.Agent.DRVH
EmsisoftTrojan.TrickBot (A)
ComodoTrojWare.Win32.Trickster.C@831h3i
DrWebTrojan.Trick.46210
ZillyaTrojan.Kryptik.Win32.1607395
TrendMicroTrojanSpy.Win32.TRICKBOT.SMTH
McAfee-GW-EditionBehavesLike.Win32.IRCBot.gc
FireEyeGeneric.mg.d5ef0ce4c5f4b5bc
SophosMal/Generic-R + Mal/Trickbot-H
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.Trickster.iy
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2AE7ABC
MicrosoftTrojan:Win32/Trickbot.PB!MTB
ArcabitTrojan.Agent.DRVH
GDataTrojan.Agent.DRVH
AhnLab-V3Malware/Win32.Generic.C3111322
Acronissuspicious
McAfeeTrojan-FQGT!D5EF0CE4C5F4
VBA32Trojan.MereTam
MalwarebytesTrojan.TrickBot
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.SMTH
RisingTrojan.Kryptik!1.B693 (CLASSIC)
YandexTrojan.GenAsa!WlTb7p5Q8rU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74137487.susgen
FortinetW32/Kryptik.GQTG!tr
BitDefenderThetaGen:NN.ZexaF.34062.D8Z@aSgVMyli
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Banker.Win32.Trickster.evk?

Trojan-Banker.Win32.Trickster.evk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment