Spy

What is “Win32/Spy.Banbra.OKD”?

Malware Removal

The Win32/Spy.Banbra.OKD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Banbra.OKD virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Win32/Spy.Banbra.OKD?


File Info:

name: 6C47719388BE33EEC992.mlw
path: /opt/CAPEv2/storage/binaries/04f3f19692c5f01b907eec3dfae5166725fb81fa010b63932b15905a05029935
crc32: B020AD83
md5: 6c47719388be33eec992f21dcdcc322b
sha1: 1f78c3b6c6ae95f7f42e07da02c03210f7927552
sha256: 04f3f19692c5f01b907eec3dfae5166725fb81fa010b63932b15905a05029935
sha512: 43a314425d40b202fbabd9f10079234cfdbe247c2b7014461b641536aee1e0d0ed43b0d4564d72a6978bfc0b5c42ef4e138f52938632798ac3690c5ed1e4383a
ssdeep: 12288:+d1sVKwFoPx/O58VsabYPb3EjZMn2oQPCV5KTa05wrn0NLKH04VZF+S+7etNrR8:SssvhLx5jZMn2oQcf05wr0N80Cyqtv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1820522FF23BC8055E02B11F561275F815A565EB829D80613336A361F0EBA2EBC1DBF46
sha3_384: 3f70e7e8b3eab1ded63a1f7e4155c00d924ee2b2f97cb704bb093c048c1192235c8b0eee186b0bd89d5a3e39d9bcffa8
ep_bytes: 60e80000000058059e0200008b3003f0
timestamp: 2014-01-02 22:11:43

Version Info:

0: [No Data]

Win32/Spy.Banbra.OKD also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Graftor.145166
FireEyeGeneric.mg.6c47719388be33ee
McAfeeArtemis!6C47719388BE
VIPREGen:Variant.Graftor.145166
K7AntiVirusSpyware ( 004df29f1 )
K7GWSpyware ( 004df29f1 )
Cybereasonmalicious.388be3
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Banbra.OKD
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Graftor.145166
NANO-AntivirusTrojan.Win32.RiskGen.dbehqq
AvastWin32:Evo-gen [Trj]
Ad-AwareGen:Variant.Graftor.145166
EmsisoftGen:Variant.Graftor.145166 (B)
ComodoTrojWare.Win32.Trojan.Banker.~d08@1okg8n
ZillyaTrojan.Banbra.Win32.24275
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.bc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.145166
GoogleDetected
AviraTR/Rogue.817664
MAXmalware (ai score=80)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
BitDefenderThetaAI:Packer.2804B69A21
ALYacGen:Variant.Graftor.145166
VBA32TScope.Trojan.Delf
MalwarebytesMalware.Heuristic.1003
RisingMalware.Undefined!8.C (TFE:5:2t8msi3vvHM)
YandexTrojan.GenAsa!yzks457Aj/U
IkarusTrojan-Downloader.Win32.Banload
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banbra.OKD!tr.spy
AVGWin32:Evo-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/Spy.Banbra.OKD?

Win32/Spy.Banbra.OKD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment