Spy

Win32/Spy.Banker.ADRS removal instruction

Malware Removal

The Win32/Spy.Banker.ADRS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Banker.ADRS virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Spy.Banker.ADRS?


File Info:

name: 923156AE4263A222F2E2.mlw
path: /opt/CAPEv2/storage/binaries/1af308ffe17789effe6d1b9a680ad112d0fc57ebf5d1f7c55bdeb7ff7edf3cd0
crc32: FDCF3258
md5: 923156ae4263a222f2e203914e368bd5
sha1: c7eed824c8bd7e9f1f1e35abcae9661a4c589061
sha256: 1af308ffe17789effe6d1b9a680ad112d0fc57ebf5d1f7c55bdeb7ff7edf3cd0
sha512: 16083b10bca7b0e88ec268f0cb776455ca8909582372adb7df784b85f8a21100cdaf405339220e95b2900bd6fcbc2e3195894487c570d09fb24397cece0b53df
ssdeep: 6144:pwY+di/Qx0ZUmuq78dHCP2TeRpEblS9OodrycQPPdslqY:pwdi4+uK8dHCiipEbstJTWlsl
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16844D016A6ACC876D42B64373CA8F7B3442E7A30693625CB33E11DE595B03907EB4397
sha3_384: c41293a38255460224ef20ca08a52cfcde5e08ea2b3cd99f32710cb681bf9cd01ae08fd75bb507998a81d5fb19883f40
ep_bytes: e8e0360000e995feffff8bff558bec81
timestamp: 2016-07-24 18:27:48

Version Info:

0: [No Data]

Win32/Spy.Banker.ADRS also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.7!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.923156ae4263a222
McAfeeArtemis!923156AE4263
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 00506b491 )
AlibabaTrojanBanker:Win32/Alreay.a2f8aac1
K7GWSpyware ( 00506b491 )
CrowdStrikewin/malicious_confidence_70% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Banker.ADRS
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Banker.Win32.Alreay.gen
BitDefenderTrojan.GenericKD.12520501
NANO-AntivirusTrojan.Win32.Alreay.euowzg
ViRobotTrojan.Win32.S.Agent.278528.WA
MicroWorld-eScanTrojan.GenericKD.12520501
AvastWin32:Malware-gen
TencentWin32.Trojan-banker.Alreay.Hqkv
Ad-AwareTrojan.GenericKD.12520501
SophosMal/Generic-S
VIPRETrojan.GenericKD.12520501
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.12520501 (B)
IkarusTrojan-Spy.Agent
GDataTrojan.GenericKD.12520501
JiangminHeur:TrojanDropper.TDSS
WebrootW32.Trojan.GenKD
AviraHEUR/AGEN.1224237
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.4956
ArcabitTrojan.Generic.DBF0C35
ZoneAlarmHEUR:Trojan-Banker.Win32.Alreay.gen
MicrosoftTrojan:Win32/Occamy.C1A
GoogleDetected
AhnLab-V3Trojan/Win32.Alreay.C2367589
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34592.ryW@aCDBg0pi
ALYacTrojan.Nukesped.A
VBA32TrojanBanker.Alreay
RisingTrojan.Generic@AI.94 (RDML:vxiaykcGix0PsoQAFBr8cQ)
YandexTrojanSpy.Banker!NRm8uzE8IkE
FortinetW32/Alreay.ADRS!tr
AVGWin32:Malware-gen
Cybereasonmalicious.e4263a
PandaTrj/GdSda.A

How to remove Win32/Spy.Banker.ADRS?

Win32/Spy.Banker.ADRS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment