Spy Trojan

How to remove “TrojanSpy:Win32/Banker!atmnm”?

Malware Removal

The TrojanSpy:Win32/Banker!atmnm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Banker!atmnm virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine TrojanSpy:Win32/Banker!atmnm?


File Info:

name: 4F1F527604B969578712.mlw
path: /opt/CAPEv2/storage/binaries/07be135580dd28e2f0dcf1ea88c08688603010b7f9edcfc37a0141ed0ecb99e7
crc32: 1EEC2043
md5: 4f1f527604b969578712e2ddab3353f3
sha1: 8b3d44a6b563bfefbe0d311fed8c954fb14260f4
sha256: 07be135580dd28e2f0dcf1ea88c08688603010b7f9edcfc37a0141ed0ecb99e7
sha512: 9455ca7289df0ca84a8f38df1c1ea13b2cb07d566ea98e69d0a7332273d25941a6fb9ae12cb05e42c58dc2c86c8b19b414b08f4a4f4285d35637b5196621041e
ssdeep: 12288:yoxejOONAM7GUC1Jr+4o628gx2Jw+tP3Jzm8JOoHXC3X+pd167QhEQO:hxY3NtGUmJr+4Obxd+tPZSZkiE6EhE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2F48D23F3D14837D1731A748C1BD2B9A826BF512D28758A7BE82D0D9F396913C392D6
sha3_384: 842dca082048b8d8b431b2fcd590d2d528c2dd0857bef139f29267f9e3dd7d5578593dde9f1b20a35a2db2384149cf04
ep_bytes: 558bec83c4f053b8547f4800e8c7d3f7
timestamp: 2008-07-23 15:21:46

Version Info:

0: [No Data]

TrojanSpy:Win32/Banker!atmnm also known as:

MicroWorld-eScanTrojan.Ranapama.AMY
ClamAVWin.Trojan.Generic-9777994-0
FireEyeGeneric.mg.4f1f527604b96957
CAT-QuickHealTrojanSpy.Banker.LY8
ALYacTrojan.Ranapama.AMY
Cylanceunsafe
ZillyaTrojan.Banker.Win32.55
SangforTrojan.Win32.Save.a
K7AntiVirusHacktool ( 005289611 )
K7GWHacktool ( 005289611 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.Banker5.ARIG
CyrenW32/Trojan.ORSB-8183
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.FakeAlert.VA
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ranapama.AMY
NANO-AntivirusTrojan.Win32.Banker.oygn
SUPERAntiSpywareTrojan.Agent/Gen-BankSpy
AvastWin32:DropperX-gen [Drp]
TencentTrojan.Win32.Fakealert.b
TACHYONBanker/W32.DP-Pharm.728576
EmsisoftTrojan.Ranapama.AMY (B)
F-SecureTrojan.TR/Delf.865208
DrWebTrojan.PWS.Gamania.10780
VIPRETrojan.Ranapama.AMY
TrendMicroTROJ_FAKEAV.SMNA
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
Trapminesuspicious.low.ml.score
SophosMal/Banker-F
IkarusTrojan-Banker.Win32.Banker
GDataWin32.Trojan.FakeAV.Q
JiangminTrojanSpy.Banker.rxi
AviraTR/Delf.865208
Antiy-AVLTrojan[Banker]/Win32.Banker
XcitiumTrojWare.Win32.TrojanDownloader.Banload.~AHI@7lad3
ArcabitTrojan.Ranapama.AMY
ViRobotTrojan.Win32.Banker.766787
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanSpy:Win32/Banker!atmnm
GoogleDetected
AhnLab-V3Trojan/Win32.Banker.R8976
McAfeeFakeAV-DR
MAXmalware (ai score=87)
VBA32TrojanPSW.Gamania
MalwarebytesFakeAlert.Trojan.Downloader.DDS
PandaTrj/Genetic.gen
ZonerTrojan.Win32.89386
TrendMicro-HouseCallTROJ_FAKEAV.SMNA
RisingDownloader.FakeAV!1.DAF2 (CLASSIC)
YandexTrojan.GenAsa!miVNfz8AUWI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FAKEAV.Q!tr
BitDefenderThetaGen:NN.ZelphiF.36196.SGW@ayJW84gO
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.604b96
DeepInstinctMALICIOUS

How to remove TrojanSpy:Win32/Banker!atmnm?

TrojanSpy:Win32/Banker!atmnm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment