Trojan

TrojanBanker.Banbra removal instruction

Malware Removal

The TrojanBanker.Banbra is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanBanker.Banbra virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine TrojanBanker.Banbra?


File Info:

crc32: 64409C04
md5: 7884019fc0b731062054ac2f0fa06e98
name: 7884019FC0B731062054AC2F0FA06E98.mlw
sha1: 843a1d6aa4f3cb45651de59ced61a20422b0942f
sha256: 3e4e7800e486d0ce046619c766aafea8edf38fe232a015a6b37983c95b282e32
sha512: 7f0283617c82f8510cca6666f5debb793af530a758154a090d8a6586fde39c758f551bcfe2b3524492531237e4a0fa986eee8d7915cdf5b07e030af3dbc20d1d
ssdeep: 24576:veunxXNtHy5+wXby/hH5Kp3iVOFWjcTfMrF0LQ:v3xNBwXb6hZKgOFWjcTfMrF0LQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2003-2010 Adobe Systems Incorporated. All rights reserved.
InternalName: ConvertIP
FileVersion: 9002, 2281, 1, 0
CompanyName: Adobe Systems Incorporated
ProductName: Adobe LiveCycle Designer Import Filter
ProductVersion: 9, 0, 0, 2, 20101008, 1, 734229
FileDescription: Adobe LiveCycle Designer Import Filter
OriginalFilename: ConvertIP.EXE
Translation: 0x0804 0x04b0

TrojanBanker.Banbra also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.72423
FireEyeGeneric.mg.7884019fc0b73106
CAT-QuickHealHacktool.Flystudio.16558
ALYacTrojan.GenericKDZ.72423
MalwarebytesTrojan.Emotet
SangforMalware
K7AntiVirusTrojan ( 005246d51 )
BitDefenderTrojan.GenericKDZ.72423
K7GWTrojan ( 00013a151 )
CrowdStrikewin/malicious_confidence_70% (D)
ArcabitTrojan.Generic.D11AE7
BitDefenderThetaGen:NN.ZexaF.34804.9q0@a41g3Vlb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Malware.Zusy-6840460-0
KasperskyHEUR:Trojan.Win32.Vimditator.gen
NANO-AntivirusTrojan.Win32.Banbra.dnbbrb
TencentWin32.Trojan.Vimditator.Aisa
Ad-AwareTrojan.GenericKDZ.72423
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
DrWebTrojan.Replacer.1
ZillyaTrojan.Banbra.Win32.22701
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftTrojan.GenericKDZ.72423 (B)
IkarusWin32.Outbreak
JiangminTrojan.Generic.eiwgq
eGambitUnsafe.AI_Score_99%
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftTrojanDownloader:Win32/Emotet!ml
ZoneAlarmHEUR:Trojan.Win32.Vimditator.gen
GDataWin32.Packed.PSE.1RYG8S7
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXBN-SB!7884019FC0B7
MAXmalware (ai score=80)
VBA32TrojanBanker.Banbra
ESET-NOD32Win32/Flyagent.NGZ
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazq0AeWenK8Tjd+TIUgzEeIG)
YandexTrojan.GenAsa!b+RJocxRF90
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AC.B9965!tr
AVGWin32:Evo-gen [Susp]

How to remove TrojanBanker.Banbra?

TrojanBanker.Banbra removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment