Spy Trojan

How to remove “TrojanSpy:Win32/Banker.ALI”?

Malware Removal

The TrojanSpy:Win32/Banker.ALI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Banker.ALI virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanSpy:Win32/Banker.ALI?


File Info:

crc32: E9AA061A
md5: 5fb6d3432a349bb756954c9071d08f15
name: 5FB6D3432A349BB756954C9071D08F15.mlw
sha1: af7bc7e166c296eed980d986e84995a25a682e37
sha256: 9f813e48d859f1eeb7412d7f43478f1885e6cfe10e9d4259d7cb61fd20a60af2
sha512: aa7cac89aa6c43e0dcb0f1c040aa8a4b51c3406e6210b33e6658a76acf906aa88fa13e1e38f8903c7d79180b653306e8dcaa6b8ab968ea078132d1fb57e15e32
ssdeep: 6144:Lm/OB9cQ+vfU0eZIpBGFk/VGgYvziwkGSoy7c5N+xk1Lql0arM/gW1LlUtqcTZQ:ic9cQ+E0eZ7NtFhLcsLqLxYLytqGZH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Banker.ALI also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0046b5101 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.60591
CynetMalicious (score: 100)
McAfeeArtemis!5FB6D3432A34
CylanceUnsafe
ZillyaTrojan.Delf.Win32.77131
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Gimemo.3a347721
K7GWTrojan ( 0046b5101 )
Cybereasonmalicious.32a349
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.RLX
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Gimemo.blga
BitDefenderGen:Trojan.TrustedZone.CGW@aGHYW3mG
NANO-AntivirusTrojan.Win32.Gimemo.edsoqn
MicroWorld-eScanGen:Trojan.TrustedZone.CGW@aGHYW3mG
TencentWin32.Trojan.Gimemo.Tapi
Ad-AwareGen:Trojan.TrustedZone.CGW@aGHYW3mG
BitDefenderThetaAI:Packer.C61BEE721D
VIPRETrojan.Win32.Generic.pak!cobra
FireEyeGeneric.mg.5fb6d3432a349bb7
EmsisoftGen:Trojan.TrustedZone.CGW@aGHYW3mG (B)
JiangminTrojan/Vilsel.egb
AviraTR/Spy.Banker.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojanSpy:Win32/Banker.ALI
AegisLabTrojan.Win32.Gimemo.4!c
GDataGen:Trojan.TrustedZone.CGW@aGHYW3mG
VBA32Hoax.Gimemo
MAXmalware (ai score=100)
PandaTrj/CI.A
RisingRansom.Gimemo!8.306 (TFE:5:uvbAHE9hRGF)
YandexTrojan.Gimemo!4zUR5T1XcXA
IkarusTrojan.Win32.Delf
FortinetW32/Delf.OIX!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove TrojanSpy:Win32/Banker.ALI?

TrojanSpy:Win32/Banker.ALI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment