Spy

Win32/Spy.Banker.AASS removal tips

Malware Removal

The Win32/Spy.Banker.AASS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Banker.AASS virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A process created a hidden window
  • A HTTP/S link was seen in a script or command line
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a hidden or system file
  • Attempts to create or modify a Browser Helper Object
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Spy.Banker.AASS?


File Info:

name: 2CDC82C47A3C3A6D34EE.mlw
path: /opt/CAPEv2/storage/binaries/b44aa8f28b292ed073a44aa003c1f4351f0994a03097c19cae8fbfef07bda12f
crc32: 092517DC
md5: 2cdc82c47a3c3a6d34ee2dde986ed37b
sha1: 552e2b1df4b40c53c485b6aea4e7069abd08ca35
sha256: b44aa8f28b292ed073a44aa003c1f4351f0994a03097c19cae8fbfef07bda12f
sha512: 77c90b51c2190b02497c778795e44fd27f2ef17784f9c6e54f1413c399c68aff668475ce619255b0fc2ec497f6ce3b03463a9b909fa1d36ef0cae5b653d5e846
ssdeep: 6144:WrKVPXbxxlR2unjVIlJA2SyAa9vGb96dEI9oW6ih:WWVv1xlXjGoaMR6VH6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12724123143F65A66F1797134135A0B75C730BBB195783F9A9D2D3B6B8F688220650B2C
sha3_384: c93bdfadef1151003394622cb054ceeef9df55bbc6343cb86b53a348b473d1799bdb78922d10d74267bfe6a89c520107
ep_bytes: 60be00a045008dbe0070faffc7879cc0
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Nizoral
FileDescription:
FileVersion: 5.2.3.3
InternalName: Setup
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0416 0x04e4

Win32/Spy.Banker.AASS also known as:

McAfeeArtemis!2CDC82C47A3C
CylanceUnsafe
SangforSpyware.Win32.Banker.8
K7AntiVirusSpyware ( 0055e3db1 )
K7GWSpyware ( 0055e3db1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Banker.AASS
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Generic
NANO-AntivirusTrojan.Win32.Banker.ewugvd
AvastWin32:Broban-C [Trj]
ComodoMalware@#32mn553xaj4z5
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericR-DJC!36AF172613C7
SentinelOneStatic AI – Suspicious PE
AviraTR/Spy.Banker.AASS.2
Antiy-AVLTrojan/Generic.ASMalwS.75975B
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
VBA32suspected of Trojan.Downloader.gen
IkarusTrojan.Win32.Spy
eGambitUnsafe.AI_Score_92%
FortinetW32/Banker.AAUS!tr.spy
BitDefenderThetaGen:NN.ZelphiF.34062.nmKfaOStLugG
AVGWin32:Broban-C [Trj]
Cybereasonmalicious.47a3c3
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Spy.Banker.AASS?

Win32/Spy.Banker.AASS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment