Spy Trojan

How to remove “TrojanSpy:Win32/Banker!dha”?

Malware Removal

The TrojanSpy:Win32/Banker!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Banker!dha virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanSpy:Win32/Banker!dha?


File Info:

crc32: 78856FCC
md5: dfd09e91b7f86a984f8687ed6033af9d
name: upload_file
sha1: b8fe7884d2dc4983fb0fbca192694ce2f4685e23
sha256: aca598e2c619424077ef8043cb4284729045d296ce95414c83ed70985c892c83
sha512: 641dd95c101ae7566defb1a24279badb8c7aa94331442e0f470866b6a1e44c8790a71e83cc1cb188d7530c08bf0e5d227d35caa9a2cf7e54d2f7319381af2d84
ssdeep: 3072:XU5r72JE+FYWR0jZLShk4cPT/QzSaQ0sCFneZTznIhZJJcrJ1GHeV9:XU5uJpYnZL05STQNddFnAnGZIrV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Banker!dha also known as:

ClamAVWin.Trojan.Agent-6971031-0
CAT-QuickHealTrojan.Win32
McAfeeGenericRXFQ-MX!DFD09E91B7F8
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Alreay.7!c
SangforMalware
K7AntiVirusSpyware ( 005198041 )
BitDefenderTrojan.GenericKD.34429601
K7GWSpyware ( 005198041 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D20D5AA1
TrendMicroTSPY_BANKER.TICBBCBF
CyrenW32/Alreay.SQQX-6406
SymantecTrojan Horse
ESET-NOD32a variant of Win32/NukeSped.HM
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 85)
KasperskyHEUR:Trojan-Banker.Win32.Alreay.gen
AlibabaTrojanSpy:Win32/Banker.19dca988
NANO-AntivirusTrojan.Win32.Alreay.htohga
MicroWorld-eScanTrojan.GenericKD.34429601
RisingTrojan.Generic@ML.100 (RDML:3y7xRwdV0Wr9dehzXps08w)
Ad-AwareTrojan.GenericKD.34429601
EmsisoftTrojan.GenericKD.34429601 (B)
ComodoTrojWare.Win32.TrojanDropper.Agent.PRQ@8agxl1
F-SecureTrojan.TR/NukeSped.paztv
ZillyaTrojan.Alreay.Win32.42
InvinceaMal/Generic-R + Troj/Steale-AHF
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeTrojan.GenericKD.34429601
SophosTroj/Steale-AHF
IkarusTrojan-Spy.Agent
JiangminTrojan.Banker.Alreay.ar
AviraTR/NukeSped.paztv
MAXmalware (ai score=100)
Antiy-AVLTrojan[Banker]/Win32.Alreay
MicrosoftTrojanSpy:Win32/Banker!dha
ViRobotTrojan.Win32.Agent.232960.P
ZoneAlarmHEUR:Trojan-Banker.Win32.Alreay.gen
GDataTrojan.GenericKD.34429601
AhnLab-V3Trojan/Win32.Alreay.C2198031
VBA32TrojanBanker.Alreay
ALYacSpyware.Banker.Alreay
TACHYONTrojan/W32.VIVACIOUSGIFT.232960
MalwarebytesBackdoor.NukeSped
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_BANKER.TICBBCBF
TencentWin32.Trojan.Spy.Wwxs
YandexTrojanSpy.Banker!OdoWOzk2HIU
eGambitUnsafe.AI_Score_98%
FortinetW32/Alreay.ADRO!tr
BitDefenderThetaGen:NN.ZexaF.34254.oqW@aGm0lXc
AVGWin32:Trojan-gen
Cybereasonmalicious.4d2dc4
AvastWin32:Trojan-gen
Qihoo-360Win32/Trojan.c8b

How to remove TrojanSpy:Win32/Banker!dha?

TrojanSpy:Win32/Banker!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment