Spy

Win32/Spy.Banker.ABFF removal

Malware Removal

The Win32/Spy.Banker.ABFF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Banker.ABFF virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the PCRat malware family

How to determine Win32/Spy.Banker.ABFF?


File Info:

name: 8BEEC2669FB718C1D374.mlw
path: /opt/CAPEv2/storage/binaries/8154ab427d8d2e2e15750acad83a604f99c38dc36fbb2272f3841f0c2b05147c
crc32: 9ABB3035
md5: 8beec2669fb718c1d374072ebc901342
sha1: 0aec2aa63dd911c7e029741c12f333d83f255b2d
sha256: 8154ab427d8d2e2e15750acad83a604f99c38dc36fbb2272f3841f0c2b05147c
sha512: 84055f799178ceb35ab1433c353e1c8eac33e6169056af0af3e675cd27982a4de50f96b7537de4076de4f83acda1220148d3360d805c2fe53bbe8139faaff7a7
ssdeep: 12288:fDWdQN2YRPVzFS0RiWWRZoJFz1cqV8Ni4+K54M8lheO1duU92tW:fDb2+9zI0RiuFzWqv4+K54Mg1dwW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17855704222C13E2DD02BA4F64D591274C56ECDD3472FA2C7AEB5F60E6D3F9C2993190A
sha3_384: 0f61f730888e5f224669c297304869c6ad7be455c9e51324e6cf32e4f3f0a4b85a8bda2fb216df5613d7494ae86ae103
ep_bytes: 558bec6aff68b8e64c00685436460064
timestamp: 2009-12-04 13:35:59

Version Info:

FileVersion: 1.0.0.0
FileDescription: 订单激活
ProductName: 订单激活
ProductVersion: 1.0.0.0
CompanyName: 购买源码联系QQ:1445531978
LegalCopyright: 购买源码联系QQ:1445531978
Comments: 订单激活
Translation: 0x0804 0x04b0

Win32/Spy.Banker.ABFF also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
ClamAVWin.Trojan.Generic-6305873-0
FireEyeGeneric.mg.8beec2669fb718c1
McAfeeGenericRXBL-YR!8BEEC2669FB7
CylanceUnsafe
SangforTrojan.Win32.Banker.ABFF
K7AntiVirusTrojan ( 005246d51 )
AlibabaBackdoor:Win32/Farfli.0327b2c7
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.63dd91
BaiduWin32.Trojan.Farfli.ag
CyrenW32/OnlineGames.HI.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Banker.ABFF
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Farfli.hkf
NANO-AntivirusTrojan.Win32.Farfli.djphlw
AvastWin32:Farfli-AR [Trj]
TencentWin32.Trojan.Gen.Eiqt
ComodoWorm.Win32.Dropper.RA@1qraug
DrWebTrojan.DownLoader9.64062
TrendMicroTROJ_GEN.R067C0OIA22
McAfee-GW-EditionGenericRXBL-YR!8BEEC2669FB7
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminHeur:Trojan/Dialer
AviraHEUR/AGEN.1207349
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Hack.Farfli.h.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34646.tv0@a8sA8Wlb
VBA32BScope.Trojan.Agent
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R067C0OIA22
RisingBackdoor.Farfli!1.A1B3 (CLASSIC)
YandexTrojan.GenAsa!XbAsGU+uby0
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.F
AVGWin32:Farfli-AR [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Spy.Banker.ABFF?

Win32/Spy.Banker.ABFF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment