Spy Trojan

TrojanSpy:Win32/Banker.VCP removal guide

Malware Removal

The TrojanSpy:Win32/Banker.VCP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Banker.VCP virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to create or modify a Browser Helper Object
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

spacemodas-gold-com.web18.redehost.com.br
transportessdl.web103.f1.k8.com.br

How to determine TrojanSpy:Win32/Banker.VCP?


File Info:

crc32: 406868D6
md5: 367d2362b744b9d4a953db397dc6db56
name: 367D2362B744B9D4A953DB397DC6DB56.mlw
sha1: 3828b67a5949d48a7f1ef36329301a8714c2b909
sha256: 5459cd921aeafae776eef1cbddf9ac7206b27a4950b8d7024efec6b0f3f7d1c0
sha512: d6879d8728aee2fb6ac5753629d62c41d4798763b4de665602bdb9dffcd4c3cd75f892dbd1b4943006a7f71475458e6ea0a83fe63f87cb0787051f594f9efd44
ssdeep: 3072:0rpfHuJS0cG/s9NH9kz1mT0AQzIsDtvo4Gi71IDnujb9UUFDEY4JlwFu341CBfq:0rpWJSmaGIwFD4i2rujb9rdmJG472M9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: down_Cliente2
FileVersion: 1.00
OriginalFilename: down_Cliente2.exe
ProductName: fitas

TrojanSpy:Win32/Banker.VCP also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.7906640
FireEyeGeneric.mg.367d2362b744b9d4
Qihoo-360HEUR/Malware.QVM03.Gen
McAfeeGenericRXLH-WX!367D2362B744
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Banload.mgKS
SangforMalware
K7AntiVirusSpyware ( 0055e3db1 )
BitDefenderTrojan.Generic.7906640
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.2b744b
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Remcos-9800818-0
KasperskyTrojan-Downloader.Win32.Banload.bxnq
AlibabaTrojanSpy:Win32/Banload.e8c7ffee
NANO-AntivirusTrojan.Win32.Dwn.vizsd
ViRobotTrojan.Win32.A.Downloader.208896.KP
RisingSpyware.Bancos!8.2F8 (CLOUD)
Ad-AwareTrojan.Generic.7906640
EmsisoftTrojan.Generic.7906640 (B)
ComodoMalware@#2h4np8yxffofj
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader6.40566
ZillyaDownloader.Banload.Win32.42415
TrendMicroTSPY_BANLOAD_CA08289B.TOMC
McAfee-GW-EditionGenericRXLH-WX!367D2362B744
SophosMal/VBInjec-B
IkarusTrojan.VB.Crypt
JiangminTrojanDownloader.Banload.bpow
WebrootW32.Trojan.Downloader
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan[Downloader]/Win32.Banload
MicrosoftTrojanSpy:Win32/Banker.VCP
ArcabitTrojan.Generic.D78A550
ZoneAlarmTrojan-Downloader.Win32.Banload.bxnq
GDataTrojan.Generic.7906640
CynetMalicious (score: 85)
BitDefenderThetaAI:Packer.CB444DC315
ALYacTrojan.Generic.7906640
MalwarebytesTrojan.Banker.Gen
PandaGeneric Malware
ESET-NOD32a variant of Win32/Spy.Bancos.NVV
TrendMicro-HouseCallTSPY_BANLOAD_CA08289B.TOMC
TencentMalware.Win32.Gencirc.114c2fca
YandexTrojan.GenAsa!lgTydFhgxA8
eGambitUnsafe.AI_Score_98%
FortinetW32/Bancos.NVV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanSpy:Win32/Banker.VCP?

TrojanSpy:Win32/Banker.VCP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment