Trojan

UDS:Trojan-Banker.Win32.Bandra.atf removal guide

Malware Removal

The UDS:Trojan-Banker.Win32.Bandra.atf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Banker.Win32.Bandra.atf virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine UDS:Trojan-Banker.Win32.Bandra.atf?


File Info:

name: 65E80868C88EE7755C1A.mlw
path: /opt/CAPEv2/storage/binaries/ab94eaeeb5f0f69611750b543827112c96062be9dd74e7f6bb7e1623455a38d5
crc32: 653D2646
md5: 65e80868c88ee7755c1a312a7ff87fdb
sha1: 1079334ac4ad344f43dbab0cf003f81c5289bb76
sha256: ab94eaeeb5f0f69611750b543827112c96062be9dd74e7f6bb7e1623455a38d5
sha512: 69d7cbc8b586e2337f99b72da21194d66744d37c265a476ba5c8c548222caba54f437285ea81b5103e68b4a8f3fd2f74b21f9d283ee7fe24fa083436f6215da9
ssdeep: 24576:ibY3CTWJQYyY4DHuNcXgMDNdM6P1SbN0dheIK2o564Z2broWLCyLh7Il3RuQ553h:XCi3LcMN0zK2o5H2bkWLCySl3l
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F7D52B135A8B0E75DDD23BB4A1CB633AA734ED30CA3A9B7FB608C53559532C46C1A742
sha3_384: 1841e94e91e716635625772b28a9a20fd462ecd5aa209357159b438d268a8f78604a887d3b18162b6a0585b021a13762
ep_bytes: 83ec0cc705b8d3540000000000e80ec3
timestamp: 2022-07-19 15:51:45

Version Info:

0: [No Data]

UDS:Trojan-Banker.Win32.Bandra.atf also known as:

CynetMalicious (score: 100)
FireEyeGen:Variant.Fragtor.118385
McAfeeGenericRXTR-GC!65E80868C88E
CylanceUnsafe
K7AntiVirusTrojan ( 0059579c1 )
K7GWTrojan ( 0059579c1 )
CyrenW32/Trojan.HLPX-5019
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQDK
KasperskyUDS:Trojan-Banker.Win32.Bandra.atf
BitDefenderGen:Variant.Fragtor.118385
MicroWorld-eScanGen:Variant.Fragtor.118385
AvastFileRepMalware [Misc]
Ad-AwareGen:Variant.Fragtor.118385
EmsisoftGen:Variant.Fragtor.118385 (B)
VIPREGen:Variant.Fragtor.118385
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1PMRMI2
ArcabitTrojan.Fragtor.D1CE71
ZoneAlarmUDS:Trojan-Banker.Win32.Bandra.atf
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.R505621
ALYacGen:Variant.Fragtor.118385
MAXmalware (ai score=87)
VBA32BScope.TrojanPSW.Arkei
MalwarebytesSpyware.PasswordStealer
RisingTrojan.Kryptik!8.8 (TFE:dGZlOgU5pikKdNIj0A)
IkarusTrojan.Win32.Krypt
MaxSecureSpy.W32.Convagent.gen_232116
FortinetW32/RedLineStealer.B!tr
AVGFileRepMalware [Misc]

How to remove UDS:Trojan-Banker.Win32.Bandra.atf?

UDS:Trojan-Banker.Win32.Bandra.atf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment