Trojan

Trojan.Banker information

Malware Removal

The Trojan.Banker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan.Banker virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

How to determine Trojan.Banker?


File Info:

crc32: D1D2A76A
md5: c3b603bc6299d576bfc0ee3c9fa3a436
name: mffb7.exe
sha1: 7c19306c508063efcd25b2e03097e8e59ec7f8ca
sha256: 299d51225c50959ef6b74013fcda1ffc8cd326f491af31636e9178cd1865cb5a
sha512: aae104c318c01fee511549e2833aeba960ba880eb6d3d24ff8883583989c909cb74aa742d763c6777620b37b20ddfa452723d5d867d3c9b64868ae7080467b1d
ssdeep: 12288:AnbptTp5FwNKbBIk2pYcgGv8X4yzCh5RKYJKDkadzAC:UHnF6K21YPGvvhamadz1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Banker also known as:

MicroWorld-eScanGen:Variant.Ulise.87427
FireEyeGeneric.mg.c3b603bc6299d576
McAfeeFareit-FQC!C3B603BC6299
CylanceUnsafe
K7AntiVirusTrojan ( 0055bb0a1 )
BitDefenderGen:Variant.Ulise.87427
K7GWTrojan ( 0055bb0a1 )
Cybereasonmalicious.c6299d
TrendMicroTrojanSpy.Win32.LOKI.SMAD1.hp
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Variant.Ulise.87427
KasperskyHEUR:Trojan-Banker.Win32.ClipBanker.gen
RisingTrojan.Injector!8.C4 (TFE:5:edSHVXX79sR)
Endgamemalicious (high confidence)
EmsisoftGen:Trojan.Heur2.LPTZGX@b0TNPnpib (B)
ZillyaTrojan.Injector.Win32.667884
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.ch
Trapminemalicious.high.ml.score
SophosMal/Fareit-V
JiangminTrojan.Banker.ClipBanker.ke
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Lokibot.CS!MTB
ArcabitTrojan.Ulise.D15583
ZoneAlarmHEUR:Trojan-Banker.Win32.ClipBanker.gen
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
ALYacGen:Variant.Ulise.87427
Ad-AwareGen:Variant.Ulise.87427
MalwarebytesTrojan.Banker
ESET-NOD32a variant of Win32/Injector.EJCD
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD1.hp
SentinelOneDFI – Suspicious PE
FortinetW32/Injector.EESQ!tr
BitDefenderThetaGen:Trojan.Heur2.LPTZGX@b0TNPnpib
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM05.1.6F5F.Malware.Gen

How to remove Trojan.Banker?

Trojan.Banker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment