Spy

Win32/Spy.Bancos.NZR removal

Malware Removal

The Win32/Spy.Bancos.NZR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Bancos.NZR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Win32/Spy.Bancos.NZR?


File Info:

name: 67110CA6A626486647B4.mlw
path: /opt/CAPEv2/storage/binaries/04044ecb079f03779249e1af23a4fea7ba23e2b207800ede007765a870517c8c
crc32: CB8D67F4
md5: 67110ca6a626486647b41b54f4f3c006
sha1: 09d0fe6569214601ab8a905afe116b30e4231bff
sha256: 04044ecb079f03779249e1af23a4fea7ba23e2b207800ede007765a870517c8c
sha512: 3a74bf1cc96bba34ccbfc91e3f4802d178f496fc1cd32ea469c44324219f79d5ffaf5da929197d1c357b273066d456952b5aeedef91b0ae569bf298e0aa1c0b5
ssdeep: 1536:bcf4iKEFXvxKqHsbJPdq/mgqHsDKEFXvxg+:bc/Xeya2mgyuXH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB83F8C3F24590A5FC9A45712537DE541E0AFE35B8D02D02768A7A5B8AB32C3A1F631F
sha3_384: daed31913d73a72c35a87d68d4be8952e5b6e266a2b1a3cea9ffe8a58227c66f7e365fc01250f85dfefce792af7d1d2b
ep_bytes: 6814754000e8eeffffff000000000000
timestamp: 2010-07-05 17:52:57

Version Info:

Translation: 0x0409 0x04b0
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: orcamento
OriginalFilename: orcamento.exe

Win32/Spy.Bancos.NZR also known as:

LionicTrojan.Win32.Swisyn.kZb9
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.fm0@sXE!Xxeif
SkyhighBehavesLike.Win32.Vilsel.mm
ALYacGen:Trojan.Heur.fm0@sXE!Xxeif
ZillyaWorm.VB.Win32.3005
AlibabaWorm:Win32/Bancos.0970064e
Cybereasonmalicious.6a6264
ArcabitTrojan.Heur.E57EC1
BitDefenderThetaAI:Packer.77EF19EA1D
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Bancos.NZR
APEXMalicious
TrendMicro-HouseCallWORM_VB.JMT
ClamAVWin.Trojan.Agent-622035
KasperskyWorm.Win32.VB.fh
BitDefenderGen:Trojan.Heur.fm0@sXE!Xxeif
NANO-AntivirusTrojan.Win32.VB.cvpoxj
AvastWin32:VB-PYJ [Drp]
EmsisoftGen:Trojan.Heur.fm0@sXE!Xxeif (B)
F-SecureTrojan.TR/Crypt.CFI.Gen
DrWebWorm.Siggen.5238
VIPREGen:Trojan.Heur.fm0@sXE!Xxeif
TrendMicroWORM_VB.JMT
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.67110ca6a6264866
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Dynamer.Gen
GoogleDetected
AviraTR/Crypt.CFI.Gen
VaristW32/VB-Document-disguised-based
Antiy-AVLWorm/Win32.VB.fh
KingsoftWin32.HeurC.KVM007.a
XcitiumWorm.Win32.VB.wdq@2nrss6
MicrosoftTrojan:Win32/Dynamer!dtc
ViRobotWorm.Win32.A.VB.81920
ZoneAlarmWorm.Win32.VB.fh
GDataGen:Trojan.Heur.fm0@sXE!Xxeif
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Genome.C66494
McAfeeGenericRXAA-AA!67110CA6A626
MAXmalware (ai score=99)
RisingMalware.FakeDOC/ICON!1.9C3B (CLASSIC)
YandexTrojan.GenAsa!CbU/Ysreskc
IkarusTrojan.Win32.VB
MaxSecureTrojan.Malware.680808.susgen
FortinetW32/VB.FH!worm
AVGWin32:VB-PYJ [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudWorm:Win/Bancos.NZR

How to remove Win32/Spy.Bancos.NZR?

Win32/Spy.Bancos.NZR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment