Trojan

How to remove “Trojan:Win32/Banker!MSR”?

Malware Removal

The Trojan:Win32/Banker!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Banker!MSR virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Banker!MSR?


File Info:

crc32: 5BACDBDF
md5: c4141ee8e9594511f528862519480d36
name: upload_file
sha1: 2b22d9c673d031dfd07986906184e1d31908cea1
sha256: 129b8825eaf61dcc2321aad7b84632233fa4bbc7e24bdf123b507157353930f0
sha512: dfc1ad2cb2df2b79ac0f2254b605a2012b94529ac220350a4075e60b06717918175cff5c22e52765237b78ec4edffd6df20f333e28a405a4339a10288158e7fc
ssdeep: 3072:lUGDXTpE8AKDKDOf+8ZagCfG4aAzFdIARrhxg6/ZpDA:+GDXTpFDKDMZagX4aAB2Cg6hpD
type: PE32 executable (DLL) (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Banker!MSR also known as:

ClamAVWin.Trojan.Alreay-7189205-0
CAT-QuickHealTrojan.Win32
McAfeeTrojan-Banking
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agent.7!c
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.32541173
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D1F089F5
InvinceaMal/Generic-R + Troj/Banker-GYS
CyrenW32/Trojan.WWWY-8606
SymantecTrojan Horse
ESET-NOD32a variant of Win32/NukeSped.GA
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 85)
KasperskyTrojan-Banker.Win32.Agent.aozp
AlibabaTrojanBanker:Win32/Banker.a06cade7
NANO-AntivirusTrojan.Win32.NukeSped.gexoae
MicroWorld-eScanTrojan.GenericKD.32541173
Ad-AwareTrojan.GenericKD.32541173
EmsisoftTrojan.GenericKD.32541173 (B)
ComodoMalware@#9ssucq4ttvda
F-SecureTrojan.TR/Spy.Banker.pubvd
ZillyaTrojan.NukeSped.Win32.183
TrendMicroBackdoor.Win32.NUKESPED.AA
McAfee-GW-EditionTrojan-Banking
FireEyeTrojan.GenericKD.32541173
SophosTroj/Banker-GYS
JiangminTrojan.Banker.Agent.csl
AviraTR/Spy.Banker.pubvd
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Tiggre
MicrosoftTrojan:Win32/Banker!MSR
ViRobotTrojan.Win32.Agent.118784.GC
ZoneAlarmTrojan-Banker.Win32.Agent.aozp
GDataTrojan.GenericKD.32541173
AhnLab-V3Trojan/Win32.Banker.C4186803
VBA32BScope.TrojanBanker.Agent
ALYacTrojan.Nukesped.A
TACHYONTrojan/W32.FASTCASH.118784
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.Win32.NUKESPED.AA
TencentWin32.Trojan-banker.Agent.Svgu
YandexTrojan.PWS.Agent!XkEps44/TGc
IkarusTrojan-Downloader.Win32.Stantinko
FortinetW32/Agent.0D36!tr
BitDefenderThetaGen:NN.ZedlaF.34254.hq4@amiSPYi
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.de4

How to remove Trojan:Win32/Banker!MSR?

Trojan:Win32/Banker!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment