Spy Trojan

TrojanSpy:Win32/Banker.LW removal

Malware Removal

The TrojanSpy:Win32/Banker.LW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Banker.LW virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Harvests information related to installed mail clients

How to determine TrojanSpy:Win32/Banker.LW?


File Info:

name: 7C839D6940069B166117.mlw
path: /opt/CAPEv2/storage/binaries/081b269d81f734e66458c62da7090ca752d616179847818879291ee6260c0e3c
crc32: B5C668A9
md5: 7c839d6940069b1661171c94785a1bad
sha1: 8e156f72b1167f1b198431240bfc997fd142565e
sha256: 081b269d81f734e66458c62da7090ca752d616179847818879291ee6260c0e3c
sha512: 1be4847d5c381394d49f059c434ce10022e8c595f13800ccd1c8ee8e21d5e37c0adcf63d9b2a575ab224346752533fda44ec4db96f6daa287b56692a87371c4e
ssdeep: 12288:J6LTH9fx+eUYY5YqYYYYY5YYYYYYYYZ7+ROQeXRpQBEk7tBCHPC:6L5b7+ROBwekf4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142C46C32F2D18537D0732E3CDC1B92B99939BE502E38A8497BE82D4C6F3569278152D7
sha3_384: 8d317b82cdf18b0776e21540fd61f08fb747f155394e28178fe639b10edf76009aa6811f998d771289c55e010062a282
ep_bytes: 558bec83c4ec33c08945ecb88c455c00
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

TrojanSpy:Win32/Banker.LW also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Zusy.380891
ClamAVWin.Trojan.Banker-22290
ALYacGen:Variant.Zusy.380891
Cylanceunsafe
ZillyaTrojan.Delf.Win32.59264
SangforTrojan.Win32.AGEN.1026065
K7AntiVirusSpyware ( 0055e3db1 )
K7GWSpyware ( 0055e3db1 )
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.Zusy.D5CFDB
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Delf.OJR
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Bublik.gen
BitDefenderGen:Variant.Zusy.380891
NANO-AntivirusTrojan.Win32.Delf.xvnrq
EmsisoftGen:Variant.Zusy.380891 (B)
F-SecureHeuristic.HEUR/AGEN.1330923
DrWebTrojan.PWS.Siggen.40592
VIPREGen:Variant.Zusy.380891
TrendMicroTSPY_BANKER.SMAW
FireEyeGeneric.mg.7c839d6940069b16
SophosTroj/Banker-FPX
IkarusTrojan-Spy.Win32.Banker
JiangminTrojan/Generic.amevc
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1330923
Antiy-AVLTrojan/Win32.Unknown
XcitiumMalware@#1r5alfavnxqmr
MicrosoftTrojanSpy:Win32/Banker.LW
ZoneAlarmHEUR:Trojan.Win32.Bublik.gen
GDataGen:Variant.Zusy.380891
GoogleDetected
AhnLab-V3Spyware/Win32.Banker.R34247
McAfeeGeneric BackDoor.h
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Banker.01673
MalwarebytesMachineLearning/Anomalous.100%
PandaGeneric Malware
TrendMicro-HouseCallTSPY_BANKER.SMAW
RisingSpyware.Delf!8.12D (TFE:3:ocEMibwRdmG)
YandexTrojan.GenAsa!v4HLJ20y2KU
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.BBYC!tr.dldr
BitDefenderThetaGen:NN.ZelphiF.36792.IGW@aepQbQc
AVGWin32:Banker-GLH [Trj]
Cybereasonmalicious.2b1167
AvastWin32:Banker-GLH [Trj]

How to remove TrojanSpy:Win32/Banker.LW?

TrojanSpy:Win32/Banker.LW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment