Spy

Win32/Spy.Banker.AEKV removal guide

Malware Removal

The Win32/Spy.Banker.AEKV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Banker.AEKV virus can do?

  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Portuguese (Brazil)
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Anomalous binary characteristics

Related domains:

ipinfo.io
rbmtec.com

How to determine Win32/Spy.Banker.AEKV?


File Info:

crc32: BB895F88
md5: d64c1df318a84e1fcb96310e3a779648
name: readerdc
sha1: 9b8fcb330e0855ee81bfa3bcadfac5269db4f78c
sha256: ecae947b06e56d472408b4e845554fad38a833b3da087a69c99a1995bba492a5
sha512: fced4bde1bb99e82f491509e62ccdb2b39879d36efeb45b1f69ce90fdf50523313bb2884ff2570ffdca4ea20fda8fdb7b0bca7ce70629b78f41f052727a25670
ssdeep: 98304:evueHwutwxcwit7n/HR1MMMMMMMM+VPYEGfHdRwkWhsjII+SyGX+HPCNjlH6Xzma:orHpGpbOdRwkhIG66tJx0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 12.15.34.16
FileDescription: Visualizador de PDF
FileVersion: 12.15.34.16
CompanyName: Adobe Acrobat Reader DC
Translation: 0x0416 0x04e4

Win32/Spy.Banker.AEKV also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.34243590
FireEyeGeneric.mg.d64c1df318a84e1f
McAfeeArtemis!D64C1DF318A8
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0056b4521 )
AlibabaTrojanSpy:Win32/Banker.bf8dc722
K7GWSpyware ( 0056b4521 )
Cybereasonmalicious.318a84
ArcabitTrojan.Generic.D20A8406
Invinceaheuristic
BitDefenderThetaAI:Packer.FF67443915
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Banker.AEKV
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Banker.Win32.Ghoul.gen
BitDefenderTrojan.GenericKD.34243590
Ad-AwareTrojan.GenericKD.34243590
EmsisoftTrojan.GenericKD.34243590 (B)
F-SecureTrojan.TR/Spy.Banker.fhdun
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
AviraTR/Spy.Banker.fhdun
FortinetW32/Banker.AEKV!tr.spy
Endgamemalicious (high confidence)
MicrosoftPUA:Win32/Caypnamer.A!ml
AegisLabTrojan.Win32.Ghoul.7!c
ZoneAlarmHEUR:Trojan-Banker.Win32.Ghoul.gen
ALYacGen:Variant.Jacard.192148
MAXmalware (ai score=89)
VBA32TScope.Trojan.Delf
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0DGR20
RisingSpyware.Banker!8.8D (CLOUD)
IkarusTrojan-Spy.Agent
eGambitUnsafe.AI_Score_99%
GDataTrojan.GenericKD.34243590
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.60e

How to remove Win32/Spy.Banker.AEKV?

Win32/Spy.Banker.AEKV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment