Spy Trojan

TrojanSpy:Win32/Bancos.AFU removal guide

Malware Removal

The TrojanSpy:Win32/Bancos.AFU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Bancos.AFU virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Anomalous binary characteristics

Related domains:

ftp.eligomisplus.com

How to determine TrojanSpy:Win32/Bancos.AFU?


File Info:

crc32: 8C7E7B8C
md5: fecc6163d0ce4c894b8ce3d5e9299cb2
name: FECC6163D0CE4C894B8CE3D5E9299CB2.mlw
sha1: 7906339d336b58f899d80ad81b9c2c55a6d225a3
sha256: 08ba0a51d617fcb1851e0aea3f7f0f1fd60e6d2c7c0a7f73e9f656b2c5accf22
sha512: 020d00524756d6c5bb24ede70a70e930b81f46b70999b2f40d29ea1d142f6c66ab74e8338982dab230973d730151ecabc785fe6947f3b7ac407662acc66e08a9
ssdeep: 12288:TT77aZpCDR42vDhUVJD5L1LgBasgaFws4:bGZmR4eh2DZWBaYV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Bancos.AFU also known as:

MicroWorld-eScanGen:Variant.Zusy.358067
FireEyeGen:Variant.Zusy.358067
ALYacGen:Variant.Zusy.358067
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Banload.a!c
SangforMalware
K7AntiVirusTrojan-Downloader ( 005705e51 )
BitDefenderGen:Variant.Zusy.358067
K7GWTrojan-Downloader ( 005705e51 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZelphiF.34804.EGW@am6@mQpG
CyrenW32/Trojan.DCA.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Banker-LDA [Trj]
ClamAVWin.Trojan.Banload-9382
KasperskyTrojan-Downloader.Win32.Banload.btev
AlibabaTrojanDownloader:Win32/Banload.85e84616
NANO-AntivirusTrojan.Win32.Banload.tmlpy
ViRobotTrojan.Win32.A.Downloader.503296.DN
RisingDownloader.Banload!8.15B (TFE:5:ocWGsQVFBND)
Ad-AwareGen:Variant.Zusy.358067
EmsisoftGen:Variant.Zusy.358067 (B)
ComodoTrojWare.Win32.TrojanDownloader.DELF.BUWV@4pji33
F-SecureTrojan.TR/Dldr.Delphi.Gen
ZillyaDownloader.Banload.Win32.44643
TrendMicroTSPY_BANKER.SMUB
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
SophosMal/Generic-S + Mal/Generic-L
JiangminTrojanDownloader.Banload.azjy
WebrootW32.Malware.Heur
AviraTR/Dldr.Delphi.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Banload
MicrosoftTrojanSpy:Win32/Bancos.AFU
ArcabitTrojan.Zusy.D576B3
SUPERAntiSpywareTrojan.Agent/Gen-Banload
ZoneAlarmTrojan-Downloader.Win32.Banload.btev
GDataWin32.Trojan.Delf.E
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Banload.R29410
McAfeeArtemis!FECC6163D0CE
VBA32TrojanDownloader.Banload
MalwarebytesMalware.AI.4185701797
PandaGeneric Malware
ZonerTrojan.Win32.7547
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.QSG
TrendMicro-HouseCallTSPY_BANKER.SMUB
TencentWin32.Trojan-downloader.Banload.Eibs
YandexTrojan.GenAsa!9y9Wbu+rx3A
IkarusTrojan-Downloader.Banload
eGambitUnsafe.AI_Score_97%
FortinetW32/Banload.QNT!tr
MaxSecureTrojan.Malware.3772266.susgen
AVGWin32:Banker-LDA [Trj]
Cybereasonmalicious.3d0ce4
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Downloader.eb4

How to remove TrojanSpy:Win32/Bancos.AFU?

TrojanSpy:Win32/Bancos.AFU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment