Spy

Win32/Spy.Bancos.AAO removal

Malware Removal

The Win32/Spy.Bancos.AAO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Bancos.AAO virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.artemon.cz
mechathlon.ismu.ac.in
tamilcinemax.net
remtl.ca
shakepay.me
ocsp.digicert.com
airlux.bg
www.airlux.bg
www.2chemodana.com.ua
2chemodana.com.ua
www.aviafilm.com.ua

How to determine Win32/Spy.Bancos.AAO?


File Info:

crc32: 8F26AA27
md5: 88d932c47e7bbf6e7ca1ca2dce8e9004
name: 88D932C47E7BBF6E7CA1CA2DCE8E9004.mlw
sha1: 5296e699db2252316bb70e6681d775afce3c8f85
sha256: b40a7532fa98f1a7d0df1e306890b75385e05b96daa9a269ea531ae6478ebf7d
sha512: 9a0422b78c4081c541e3347328b2fe7b90fe0c0612d1728f6442fc77d310b2c4cb24b109f9e986010026211c617affee7fdac1c8835f727b6a62f48568b7c468
ssdeep: 3072:16+m/diAnd4dAg9qKG7pFEXsTAyqJ/cv8m9nsYq5TKFLKEnICP:u1iAnd4dAg93G7pFQpm9shdOI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: hy
FileVersion: 1.00
OriginalFilename: hy.exe
ProductName: hy

Win32/Spy.Bancos.AAO also known as:

BkavW32.AIDetect.malware2
K7AntiVirusNetWorm ( 700000151 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Symmi.2696
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.47e7bb
CyrenW32/VB.BZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Bancos.AAO
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Cossta.akoo
BitDefenderGen:Variant.Symmi.2696
NANO-AntivirusTrojan.Win32.Cossta.exevjg
MicroWorld-eScanGen:Variant.Symmi.2696
TencentWin32.Trojan.Cossta.Edob
Ad-AwareGen:Variant.Symmi.2696
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34790.jm0@aeOUU5ji
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
FireEyeGeneric.mg.88d932c47e7bbf6e
EmsisoftGen:Variant.Symmi.2696 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/ATRAPS.Gen2
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.13ADA31
MicrosoftVirTool:Win32/Obfuscator.JZ
AegisLabTrojan.Win32.Cossta.4!c
GDataGen:Variant.Symmi.2696
AhnLab-V3Trojan/Win32.Cossta.R76202
McAfeeGenericRXHS-EI!88D932C47E7B
MAXmalware (ai score=99)
VBA32TScope.Trojan.VB
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!bw2qzGemyXw
IkarusTrojan.Win32.Cossta
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bancos.AAO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.FRS.HwMAEpsA

How to remove Win32/Spy.Bancos.AAO?

Win32/Spy.Bancos.AAO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment