Spy Trojan

TrojanSpy.Banker.LY8 removal guide

Malware Removal

The TrojanSpy.Banker.LY8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy.Banker.LY8 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanSpy.Banker.LY8?


File Info:

crc32: 76D65E22
md5: bd1e75017de8ecbb357b864f6defbdc7
name: BD1E75017DE8ECBB357B864F6DEFBDC7.mlw
sha1: cd0be3639d4b1e0b45fa2dd0354dc1391d92abfb
sha256: 9c45539ba726e5454a44f7312cbb163714ebaa3ebe55f0673540943ede803486
sha512: 4461b86429893158a88ead46c83ca8bfefb7583605740ffec11d92889cb231d6ed0758cb1d9f390c82fa1a28b0bcc1615b19206c2e3e8718589a71c44b18ff0f
ssdeep: 24576:hxY3NtGUmJr+4Obxd+tPZSZBiE6EhE9xY3NtGUmJL:LY3buzMi0IY3buL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy.Banker.LY8 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ranapama.AMY
FireEyeGeneric.mg.bd1e75017de8ecbb
CAT-QuickHealTrojanSpy.Banker.LY8
ALYacTrojan.Ranapama.AMY
MalwarebytesGeneric.Trojan.Banker.DDS
SangforMalware
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan-Downloader ( 0001b7311 )
K7AntiVirusTrojan-Downloader ( 0001b7311 )
CyrenW32/Trojan.ORSB-8183
SymantecTrojan.FakeAV
TotalDefenseWin32/Oneraw.JJ
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Trojan.Generic-9777994-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ranapama.AMY
NANO-AntivirusTrojan.Win32.Banker.oygn
ViRobotTrojan.Win32.Banker.766787
RisingDownloader.FakeAlert!8.4FF (TFE:4:gZaiDzu7H9B)
Ad-AwareTrojan.Ranapama.AMY
SophosML/PE-A + Mal/Banker-F
ComodoTrojWare.Win32.TrojanDownloader.Banload.~AHI@7lad3
F-SecureTrojan.TR/Delf.865208
DrWebTrojan.PWS.Gamania.10780
TrendMicroTROJ_FAKEAV.SMNA
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftTrojan.Ranapama.AMY (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.FakeAV.Q
JiangminTrojanSpy.Banker.rxi
AviraTR/Delf.865208
Antiy-AVLTrojan[Banker]/Win32.Banker
ArcabitTrojan.Ranapama.AMY
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanSpy:Win32/Banker.LY
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Banker.R8976
Acronissuspicious
McAfeeFakeAV-DR
MAXmalware (ai score=85)
VBA32TrojanPSW.Gamania
CylanceUnsafe
ZonerTrojan.Win32.89386
ESET-NOD32a variant of Win32/TrojanDownloader.FakeAlert.VA
TrendMicro-HouseCallTROJ_FAKEAV.SMNA
TencentTrojan.Win32.Fakealert.b
YandexTrojan.GenAsa!miVNfz8AUWI
TACHYONTrojan/W32.DP-Ranapama.1048576
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FAKEAV.Q!tr
BitDefenderThetaAI:Packer.E13D85A419
AVGWin32:DropperX-gen [Drp]
Qihoo-360HEUR/QVM05.1.08BC.Malware.Gen

How to remove TrojanSpy.Banker.LY8?

TrojanSpy.Banker.LY8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment