Spy Trojan

TrojanSpy:Win32/Bancos.AHL removal instruction

Malware Removal

The TrojanSpy:Win32/Bancos.AHL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Bancos.AHL virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.cadastramento.net

How to determine TrojanSpy:Win32/Bancos.AHL?


File Info:

crc32: C8562DBC
md5: fa93823acbadfce2bb196a6d0c25791d
name: FA93823ACBADFCE2BB196A6D0C25791D.mlw
sha1: 8d591728945713304ccd8200114194becb10dae7
sha256: 11f89cf974a17f4c0d4edff9499d8994d81af5bd88f2b380c5461af1f56a5996
sha512: 56010d6182c2d2d3ae6e29b243ada908427e6994b8690dbeae3b5453a554e73eff6f4e536c0b9a2d3103dd28c0ebef29d155cb757fb7ddb349feeb6d7550deb6
ssdeep: 12288:gomMutOOuutKFzuLVz/kswsUQplhYjj03EP2XvronPJ:oaz2qsEQpgPoEP8OJ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Adobe Flash Player
InternalName: Adobe Flash Player Control Panel Applet 11.2
FileVersion: 11.2.202.235
CompanyName: Adobe Systems Incorporated
PrivateBuild: Adobe Systems Incorporated
LegalTrademarks: Adobe Flash Player
Comments: Adobe Systems Incorporated
ProductName: Adobe Flash Player Control Panel Applet
SpecialBuild: Adobe Systems Incorporated
ProductVersion: 11.2.202.235
FileDescription: Adobe Flash Player Control Panel Applet
OriginalFilename: Adobe Flash Player Control Panel Applet 11.2
Translation: 0x0416 0x04e4

TrojanSpy:Win32/Bancos.AHL also known as:

MicroWorld-eScanGen:Variant.Strictor.48938
FireEyeGeneric.mg.fa93823acbadfce2
ALYacGen:Variant.Strictor.48938
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderGen:Variant.Strictor.48938
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.acbadf
BitDefenderThetaGen:NN.ZelphiF.34804.CmKfa8xPtPoO
CyrenW32/Bancos.AA.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Spyware-gen [Spy]
ClamAVWin.Trojan.Agent-433581
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Bancos.brkeva
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Generic.Efkl
Ad-AwareGen:Variant.Strictor.48938
SophosMal/Generic-R + Mal/BankFLA-A
ComodoMalware@#vpu0fblz5dj0
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.DownLoader7.10025
ZillyaTrojan.ProxyChanger.Win32.539
TrendMicroTROJ_GEN.R002C0DLL20
McAfee-GW-EditionBehavesLike.Win32.Dropper.gc
EmsisoftGen:Variant.Strictor.48938 (B)
SentinelOneStatic AI – Suspicious PE – Adware
WebrootW32.Trojan.Gen
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[Downloader]/Win32.Agent
MicrosoftTrojanSpy:Win32/Bancos.AHL
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Strictor.DBF2A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Strictor.48938
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Genome.R12306
McAfeeArtemis!FA93823ACBAD
MAXmalware (ai score=86)
VBA32BScope.Trojan.Agent
MalwarebytesMalware.AI.476852788
PandaTrj/CI.A
ESET-NOD32a variant of Win32/ProxyChanger.DX
TrendMicro-HouseCallTROJ_GEN.R002C0DLL20
RisingTrojan.Win32.Generic.1338CF1A (C64:YzY0OlMM/vIl+Bbe)
YandexTrojan.GenAsa!StMHGSuFjxY
IkarusTrojan.Win32.ProxyChanger
eGambitUnsafe.AI_Score_99%
FortinetW32/ProxyChanger.DF!tr
AVGWin32:Spyware-gen [Spy]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/Malware.QVM11.Gen

How to remove TrojanSpy:Win32/Bancos.AHL?

TrojanSpy:Win32/Bancos.AHL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment