Trojan

About “TrojanBanker.NeutrinoPOS” infection

Malware Removal

The TrojanBanker.NeutrinoPOS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanBanker.NeutrinoPOS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine TrojanBanker.NeutrinoPOS?


File Info:

crc32: 9E571A90
md5: 01a09581d3fd41c563e24721e96c87d0
name: 01A09581D3FD41C563E24721E96C87D0.mlw
sha1: 8a5eb5db257729f31f9774d9e155e0d232bf7fc0
sha256: 7b4c276315bf72993f172fd98be4e9ff07b26d9bc3e3c49843319bc0e98441af
sha512: b20e63420fc6f6b3cff5871b74d3bb0c3374d9f805273b36b8f2d9a4aafa65319a98b36ccdaaa96fa42aeee0ea110db51b7c163e020058361b778fad511acb3d
ssdeep: 3072:vUjphKJ81D8lxmsmfP1bEwpOJAK3b2SVgBIMkiFrm0l4eYQQhoceXVsvT9B79:UpValxmsGNbEwp1KSSV+iiFrmaQ1Z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanBanker.NeutrinoPOS also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24483
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.BRMon.Gen.3
CylanceUnsafe
ZillyaTrojan.GandCrypt.Win32.26
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Gandcrab.f17b1c37
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.1d3fd4
CyrenW32/S-dea5fd14!Eldorado
ESET-NOD32Win32/Filecoder.GandCrab.B
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Gandcrab-6502433-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BRMon.Gen.3
NANO-AntivirusTrojan.Win32.NeutrinoPOS.expauo
ViRobotTrojan.Win32.Agent.248832.F
MicroWorld-eScanTrojan.BRMon.Gen.3
TencentMalware.Win32.Gencirc.10b73c30
Ad-AwareTrojan.BRMon.Gen.3
SophosML/PE-A + Mal/Ransom-FN
ComodoApplication.Win32.IStartSurf.PS@8c4m91
BitDefenderThetaGen:NN.ZexaF.34608.puW@au9pmFe
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMONT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.01a09581d3fd41c5
EmsisoftTrojan.BRMon.Gen.3 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117310
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Gandcrab.GM!MTB
AegisLabTrojan.Win32.Generic.4!c
GDataWin32.Trojan-Ransom.GandCrab.N
TACHYONRansom/W32.GandCrypt.248832.B
AhnLab-V3Trojan/Win.MalPe.X2055
Acronissuspicious
McAfeePacked-ZG!01A09581D3FD
MAXmalware (ai score=97)
VBA32TrojanBanker.NeutrinoPOS
MalwarebytesTrojan.Bunitu
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMONT
RisingMalware.Strealer!8.1EF (CLOUD)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.BOUD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCtwMA

How to remove TrojanBanker.NeutrinoPOS?

TrojanBanker.NeutrinoPOS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment