Trojan

TrojanBanker.Agent information

Malware Removal

The TrojanBanker.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanBanker.Agent virus can do?

  • Reads data out of its own binary image
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanBanker.Agent?


File Info:

crc32: F658A686
md5: 9ea456a1ebc7ab71d7e4f8b39d8ec999
name: 9EA456A1EBC7AB71D7E4F8B39D8EC999.mlw
sha1: 77498961cbb98b9089c8c581c2e3b272cd679c82
sha256: 631bc2c95c666989fa405feda74b9870044a4abc6b9ea4ff1fb0e74e556a72d2
sha512: b3fd6d1c01279dd1da71082b7572ccd92f53a53d9e24fd9a211f4ce915bfc11d82ff14ccc13a14f6d7b66f8cdc11e13a20f4ef811e548fd2b451370a7ba35b6d
ssdeep: 24576:iRmJkcoQricOIQxiZY1iaprkF8YaTzK7I6mo7S:3JZoQrbTFZY1iap4FQ67I6b7S
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

TrojanBanker.Agent also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 004fbe541 )
DrWebTrojan.Encoder.24597
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Agent
ALYacGen:Variant.Ursu.519232
CylanceUnsafe
SangforRansom.Win32.Locked.3D08AF5C
CrowdStrikewin/malicious_confidence_90% (D)
K7GWSpyware ( 004fbe541 )
Cybereasonmalicious.1ebc7a
CyrenW32/AutoIt.AQ2.gen!Eldorado
SymantecRansom.Cryptolocker
ESET-NOD32multiple detections
APEXMalicious
AvastAutoIt:Ransom-L [Trj]
ClamAVWin.Malware.Autoit-6992337-0
KasperskyTrojan-Banker.Win32.Agent.yhk
BitDefenderGeneric.Ransom.Locked.767B115C
NANO-AntivirusTrojan.Win32.Bankfraud.efjtmx
MicroWorld-eScanGeneric.Ransom.Locked.767B115C
TencentWin32.Trojan-banker.Agent.Hxqa
Ad-AwareGeneric.Ransom.Locked.767B115C
SophosMal/Generic-S
ComodoMalware@#3f4vqnl4iy05z
BitDefenderThetaAI:Packer.4A72867A16
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.AutoIt.CRYPTEIGHT.SMTH
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.9ea456a1ebc7ab71
EmsisoftGeneric.Ransom.Locked.767B115C (B)
JiangminTrojan.Banker.Agent.cal
AviraTR/Bancker.8888
eGambitUnsafe.AI_Score_84%
Antiy-AVLTrojan/Generic.ASCommon.1A0
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftRansom:Win32/Pocrimcrypt.A
GDataGen:Variant.Ursu.519232 (2x)
AhnLab-V3Trojan/Win32.Agent.C2448848
McAfeeGeneric.dqy
MAXmalware (ai score=99)
VBA32TrojanBanker.Agent
MalwarebytesMalware.AI.3512376734
PandaTrj/CI.A
TrendMicro-HouseCallRansom.AutoIt.CRYPTEIGHT.SMTH
RisingTrojan.Generic@ML.87 (RDML:TcFdWgvvuTVGFg68ZC1SFw)
IkarusTrojan-Ransom.Crypt888
MaxSecureTrojan.Autoit.AZA
FortinetW32/Filecoder.DYB!tr
AVGAutoIt:Ransom-L [Trj]
Paloaltogeneric.ml

How to remove TrojanBanker.Agent?

TrojanBanker.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment