Spy

Win32/Spy.Banker.ANV removal guide

Malware Removal

The Win32/Spy.Banker.ANV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Banker.ANV virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Spy.Banker.ANV?


File Info:

name: A2646076F92175384AAA.mlw
path: /opt/CAPEv2/storage/binaries/0d8f1751962c13d6967e5d57486a3d97155e88d25db8146bac093f6d2e21c090
crc32: A36A1398
md5: a2646076f92175384aaa3db7454e18ec
sha1: 19eab97261cfb6a564bcbb6563e80b587e290c88
sha256: 0d8f1751962c13d6967e5d57486a3d97155e88d25db8146bac093f6d2e21c090
sha512: 051e7208b56b6b6960e4320c24c00f177288ba581a7dfc5cde633089678b6f5188228b94844da97691345900f1dbbe77b08170672f2456c2a1d6061a4810d60e
ssdeep: 12288:1cxxXs7QRYZeB74j5865jiLVKGoT8WiYLc0U3k4d4Lz9FDs9L8hgNgI1uMQjuMQV:1YJspZeB74LhkuwaCxyf9cwhgNg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C216635E7D33B100D421523F7B458FD958BA6FCBEB26F82226983ACDD57BAC06E10119
sha3_384: aee81776d56a2167d994ffe84b7cb16ebddd43be550786e33d11fa5e6b9b0929db57774a8d09bb5c7df611a270a1f08c
ep_bytes: 558bec83c4f053b864b34900e88badf6
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Spy.Banker.ANV also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Crypt.Delf.B
FireEyeGeneric.mg.a2646076f9217538
CAT-QuickHealTrojan.Banker.18256
SkyhighBehavesLike.Win32.Generic.rt
McAfeePWS-Banker.gen.t
MalwarebytesBanker.Trojan.Stealer.DDS
ZillyaTrojan.Banker.Win32.31881
SangforTrojan.Win32.Save.a
AlibabaTrojanDownloader:Win32/Banload.48c929bc
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZelphiF.36802.@lW@aG2951gG
SymantecInfostealer.Bancos
ESET-NOD32a variant of Win32/Spy.Banker.ANV
APEXMalicious
TrendMicro-HouseCallTSPY_BANCOS.GEN
AvastWin32:Banker-AGA [Trj]
ClamAVWin.Trojan.Bancos-830
KasperskyHEUR:Trojan-Dropper.Win32.Sysn.gen
BitDefenderTrojan.Crypt.Delf.B
NANO-AntivirusTrojan.Win32.Banker.cipxd
TencentWin32.Trojan-Dropper.Sysn.Cdhl
SophosMal/DelpBanc-A
BaiduWin32.Trojan-Spy.Banker.a
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.PWS.Banker.3375
VIPRETrojan.Crypt.Delf.B
TrendMicroTSPY_BANCOS.GEN
Trapminemalicious.high.ml.score
EmsisoftTrojan.Crypt.Delf.B (B)
GDataWin32.Trojan.PSE.N540AG
JiangminTrojanSpy.Banker.fxu
ALYacTrojan.Crypt.Delf.B
WebrootW32.Malware.Gen
VaristW32/Banker.D.gen!Eldorado
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Banker]/Win32.Banker
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.Spy.Banker.Gen@1qlojk
ArcabitTrojan.Crypt.Delf.B
ZoneAlarmHEUR:Trojan-Dropper.Win32.Sysn.gen
MicrosoftTrojanDownloader:Win32/Banload.gen!N
CynetMalicious (score: 100)
VBA32BScope.Trojan.Cosmu
GoogleDetected
Cylanceunsafe
PandaTrj/Banker.ITS
RisingSpyware.Banker!1.CEB7 (CLASSIC)
YandexTrojan.GenAsa!zmW6MkfU2Dw
IkarusTrojan-Banker.Win32.Banker
MaxSecureTrojan.Malware.1272176.susgen
FortinetW32/Banker.BIG!tr
AVGWin32:Banker-AGA [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/Banker.ANV

How to remove Win32/Spy.Banker.ANV?

Win32/Spy.Banker.ANV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment