Spy Trojan

Should I remove “TrojanSpy:Win32/Banker!pz”?

Malware Removal

The TrojanSpy:Win32/Banker!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Banker!pz virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine TrojanSpy:Win32/Banker!pz?


File Info:

name: D3CBE9884B6F30AECBB3.mlw
path: /opt/CAPEv2/storage/binaries/f97b7712e616b8282f692c0f74b2ec97674122f3b5a438071de97ca1c3b542ab
crc32: A5BDBDF1
md5: d3cbe9884b6f30aecbb3cb0cd703389a
sha1: 4751f6aa2faf600aa42c8d57e797c680f6c3d750
sha256: f97b7712e616b8282f692c0f74b2ec97674122f3b5a438071de97ca1c3b542ab
sha512: ef9bded049aebd84d47146f4cc01095baf9451971c1970e0098ce0e3814012f6cba01c8b3c7198ef737487588e5cd11363d4fc39375e4e795ce7dba32f8bf33c
ssdeep: 12288:yoxejOONAM7GUC1Jr+4o628gx2Jw+tP3Jzm8JOJHXC3X+pd167QhEQO:hxY3NtGUmJr+4Obxd+tPZSZFiE6EhE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11CF48D23F3D14837D1731A748C1BD2B9A826BF512D28758A7BE82D0D9F396913C392D6
sha3_384: 666ed1116c5c420cae567189a4bf592f2b97ff6325bfbcdeaa2a5b79a411fd13bba456a3bddeb72cdcc228368f2cfac1
ep_bytes: 558bec83c4f053b8547f4800e8c7d3f7
timestamp: 2008-07-23 15:21:46

Version Info:

0: [No Data]

TrojanSpy:Win32/Banker!pz also known as:

BkavW32.Common.C06B11D8
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Gamania.10780
MicroWorld-eScanTrojan.Ranapama.AMY
ClamAVWin.Trojan.Generic-9777994-0
FireEyeGeneric.mg.d3cbe9884b6f30ae
CAT-QuickHealTrojanSpy.Banker.LY8
McAfeeFakeAV-DR
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Banker.Win32.55
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a5d8b1 )
K7GWTrojan ( 005a5d8b1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZelphiF.36662.SGW@ayJW84gO
VirITTrojan.Win32.Banker5.ARIG
CyrenW32/Trojan.ORSB-8183
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.FakeAlert.VA
ZonerTrojan.Win32.89386
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Dropper.Win32.Daws.gen
BitDefenderTrojan.Ranapama.AMY
NANO-AntivirusTrojan.Win32.Banker.oygn
SUPERAntiSpywareTrojan.Agent/Gen-BankSpy
AvastWin32:DropperX-gen [Drp]
TencentTrojan.Win32.Fakealert.b
EmsisoftTrojan.Ranapama.AMY (B)
F-SecureTrojan.TR/Delf.865208
VIPRETrojan.Ranapama.AMY
TrendMicroTROJ_FAKEAV.SMNA
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
Trapminesuspicious.low.ml.score
SophosMal/Banker-F
IkarusTrojan-Banker.Win32.Banker
GDataWin32.Trojan.FakeAV.Q
JiangminTrojanSpy.Banker.rxi
WebrootW32.Trojan.Gen
AviraTR/Delf.865208
MAXmalware (ai score=89)
Antiy-AVLTrojan[Banker]/Win32.Banker
XcitiumTrojWare.Win32.TrojanDownloader.Banload.~AHI@7lad3
ArcabitTrojan.Ranapama.AMY
ViRobotTrojan.Win32.Banker.766787
ZoneAlarmHEUR:Trojan-Dropper.Win32.Daws.gen
MicrosoftTrojanSpy:Win32/Banker!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Banker.R8976
Acronissuspicious
VBA32TrojanPSW.Gamania
ALYacTrojan.Ranapama.AMY
TACHYONBanker/W32.DP-Pharm.728576
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FAKEAV.SMNA
RisingDownloader.FakeAV!1.DAF2 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FAKEAV.Q!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.a2faf6
DeepInstinctMALICIOUS

How to remove TrojanSpy:Win32/Banker!pz?

TrojanSpy:Win32/Banker!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment