Spy Trojan

TrojanSpy:Win32/Banker.DFA malicious file

Malware Removal

The TrojanSpy:Win32/Banker.DFA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Banker.DFA virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine TrojanSpy:Win32/Banker.DFA?


File Info:

name: 9DF24660D96A7435D9D3.mlw
path: /opt/CAPEv2/storage/binaries/22d066b4c509b8283c7b5d87d5c406ba6a4ad30eaeea1429633f06f76c6deb5f
crc32: 47825037
md5: 9df24660d96a7435d9d3d57cfc483383
sha1: d3bfde629a416fa8b757f2c42ca3249e8680cd49
sha256: 22d066b4c509b8283c7b5d87d5c406ba6a4ad30eaeea1429633f06f76c6deb5f
sha512: e90c46cfeb2312259850bcaac21766391f7fa439fa7815d4d07d1a49a1dd57e15d4839964d92297bb5ffdb6d682efb8725bf0d3201cd32be4f25860a93b5e4e3
ssdeep: 1536:X9qCsmQwoNgA1JFGlOR62xP2+cTspgLMDy8:dFobfFGlORHPFcrLon
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E739EC3F1A284F2E042DBB74851C556DA3766B51F9402C3E6FD89ED29A83D0643BE93
sha3_384: bde1f80225df8cee05521a4ff10f774e14ee1ade89f8b7bad133fdc4a303b7c08fe081bbf3289082b311b3ea2a102e12
ep_bytes: 558bec83c4e053565733c08945e08945
timestamp: 2065-05-22 15:00:38

Version Info:

0: [No Data]

TrojanSpy:Win32/Banker.DFA also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Vaklik.llMN
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Trojan.Spy.Delf.MQ
FireEyeGeneric.mg.9df24660d96a7435
McAfeeArtemis!9DF24660D96A
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.klt (mx-v)
AlibabaTrojanSpy:Win32/KeyLogger.eb224e86
Cybereasonmalicious.0d96a7
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.KPXQSDP
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.aifoj
BitDefenderDropped:Trojan.Spy.Delf.MQ
NANO-AntivirusTrojan.Win32.MLW.dmkuh
AvastWin32:Binder-DL [Drp]
TencentWin32.Trojan-spy.Keylogger.Hzdi
Ad-AwareDropped:Trojan.Spy.Delf.MQ
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.KeyLogger.16374
ZillyaTrojan.Delf.Win32.87466
TrendMicroTROJ_GEN.R002C0DKN21
McAfee-GW-EditionBehavesLike.Win32.Lockbit.lt
EmsisoftDropped:Trojan.Spy.Delf.MQ (B)
SentinelOneStatic AI – Malicious PE
GDataDropped:Trojan.Spy.Delf.MQ
eGambitGeneric.PSW
AviraDR/Delphi.Gen
MicrosoftTrojanSpy:Win32/Banker.DFA
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaAI:Packer.633541501F
ALYacDropped:Trojan.Spy.Delf.MQ
MAXmalware (ai score=97)
VBA32TrojanSpy.KeyLogger
TrendMicro-HouseCallTROJ_GEN.R002C0DKN21
YandexTrojan.GenAsa!+Kayu0Gg9s4
IkarusEmail-Worm.Win32.Delf
MaxSecureTrojan.Malware.1728101.susgen
FortinetBanker.HB3!tr.pws
WebrootW32.Trojan.Spy.Delf
AVGWin32:Binder-DL [Drp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove TrojanSpy:Win32/Banker.DFA?

TrojanSpy:Win32/Banker.DFA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment