Spy Trojan

TrojanSpy:Win32/Banker.YT removal tips

Malware Removal

The TrojanSpy:Win32/Banker.YT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Banker.YT virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering

How to determine TrojanSpy:Win32/Banker.YT?


File Info:

name: 8F9CABBF94E54E3071D3.mlw
path: /opt/CAPEv2/storage/binaries/06c601146b14166888d489cd59b280811082801fbe2c9665d5c09183d2588b51
crc32: 5EA4D408
md5: 8f9cabbf94e54e3071d3cd56a0dba0e1
sha1: 42e3d0d67b5bc5dcb64d2907af90fadd0cd2b2b6
sha256: 06c601146b14166888d489cd59b280811082801fbe2c9665d5c09183d2588b51
sha512: 2690d99808ce20873c191d06fbd6db109bf0ac61acb4ea4a7658bee30b8b869d8089ac992d2b08c61e7f9e3ed6d65526fbba0ac6262a68911915e963e9fa62f7
ssdeep: 24576:WXMapiw+uJpyax/PEziGA83BBvtBXSOmBaXn7XhQYBF9Zs6FDWMQaUF5qJpC5uOb:WbexRSVaXzhQwi6BJJpC5u+L8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T102B55D16A294523BF4321B3A5C1B9390583F7F232975CC5F2FB47A4E0F39A01AE2565B
sha3_384: ffbe90087bb236a528b5da9d87922ecd0ef532482b827248977c72b474f10f17fc2ca9140c7d27f20ec83217ce16066c
ep_bytes: 558bec83c4f0b8f0d45b00e89c2ae4ff
timestamp: 2011-06-27 15:11:30

Version Info:

0: [No Data]

TrojanSpy:Win32/Banker.YT also known as:

BkavW32.Common.9833809A
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.302465
SkyhighBehavesLike.Win32.Dropper.vh
McAfeeArtemis!8F9CABBF94E5
MalwarebytesBanker.Trojan.Stealer.DDS
VIPREGen:Variant.Zusy.302465
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 7000000f1 )
VirITTrojan.Win32.Siggen2.CXEP
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Banker.VPH
TrendMicro-HouseCallMal_Banker11
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.302465
NANO-AntivirusTrojan.Win32.Banker.efbzn
AvastWin32:Delf-PUN [Trj]
TencentWin32.Trojan.Generic.Qzfl
EmsisoftGen:Variant.Zusy.302465 (B)
GoogleDetected
F-SecureTrojan.TR/Spy.Banker.Gen
DrWebTrojan.Siggen2.50819
ZillyaTrojan.Banker.Win32.44346
TrendMicroMal_Banker11
FireEyeGeneric.mg.8f9cabbf94e54e30
SophosMal/Generic-S
JiangminTrojan/Banker.Banker.tdy
WebrootW32.Trojan.Gen
VaristW32/ArchSMS.BS.gen!Eldorado
AviraTR/Spy.Banker.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Agent
MicrosoftTrojanSpy:Win32/Banker.YT
XcitiumTrojWare.Win32.TrojanSpy.Bancos.~NAB@38w00a
ArcabitTrojan.Zusy.D49D81
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.302465
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Banker.R10106
VBA32TrojanBanker.Banker
ALYacGen:Variant.Zusy.302465
TACHYONTrojan-Spy/W32.DP-Banker.2352128.J
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.100 (RDML:OcWww+QgrnXYphS0HZEqhQ)
IkarusTrojan-Banker.Win32.Banker
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaAI:Packer.A4E89AC51D
AVGWin32:Delf-PUN [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan

How to remove TrojanSpy:Win32/Banker.YT?

TrojanSpy:Win32/Banker.YT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment