Spy

Win32/Spy.Banker.OWM removal tips

Malware Removal

The Win32/Spy.Banker.OWM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Banker.OWM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Spy.Banker.OWM?


File Info:

name: 7D108F555231E30DFD30.mlw
path: /opt/CAPEv2/storage/binaries/01625ee770a1411d5d2ed28655f5c292a4d59cbb39502d3ed5b38fdb593e6351
crc32: 57691072
md5: 7d108f555231e30dfd30d8db7d502dbf
sha1: 59f4d67f02e21a2235c793359b5d2ed18cd28fe6
sha256: 01625ee770a1411d5d2ed28655f5c292a4d59cbb39502d3ed5b38fdb593e6351
sha512: 0424f50176e423f3cc32c4435ac0584aad511ca4e24e2c2d1f781b221df07d163c91bde4036dc87bd491d678afce41b14b935a0931d25048c68a6b7d219d2624
ssdeep: 24576:IhrsZATKTsjPbWn6uj4IOjL6MY+r27jpNlt:IhAZibbMBMIOj+MYnZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5353327AB8CFD7DF0B645393DE61B1C4E824CB536C7AA96DC52AE582D0B073884E54C
sha3_384: 0929e72fa3c154bcbfb51e1a67f289fd3f466e1b56c85a205e9d35a31f7edd29eaa74fdf2d019967b542354221049e89
ep_bytes: b868945f005064ff3500000000648925
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Spy.Banker.OWM also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Banker.Delf.1
FireEyeGeneric.mg.7d108f555231e30d
SkyhighPWS-Banker.gen.aa
McAfeePWS-Banker.gen.aa
Cylanceunsafe
ZillyaDownloader.Agent.Win32.16248
K7AntiVirusTrojan ( 0001140e1 )
AlibabaTrojanSpy:Win32/Banker.24a62aab
K7GWTrojan ( 0001140e1 )
Cybereasonmalicious.f02e21
ArcabitTrojan.Banker.Delf.1
BitDefenderThetaAI:Packer.CD97EAF91C
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Spy.Banker.OWM
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Heur.Banker.Delf.1
NANO-AntivirusTrojan.Win32.Agent.dqiidh
AvastWin32:Banker-LKS [Trj]
TencentWin32.Trojan.Spy.Lzfl
EmsisoftGen:Heur.Banker.Delf.1 (B)
F-SecureTrojan.TR/Spy.Banker.Gen
DrWebTrojan.DownLoad1.14915
VIPREGen:Heur.Banker.Delf.1
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Agent.dnyu
WebrootTrojan:Win32/Sisron
GoogleDetected
AviraTR/Spy.Banker.Gen
Antiy-AVLTrojan[Downloader]/Win32.Agent
Kingsoftmalware.kb.a.995
XcitiumTrojWare.Win32.Spy.Banker.Gen@1qlojk
MicrosoftTrojan:Win32/Sisron!gmb
ViRobotSpyware.Agent.Do.1112064.B
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Heur.Banker.Delf.1
VaristW32/D_Bancos!Generic
AhnLab-V3Trojan/Win32.Banker.C17011
VBA32suspected of Trojan-Spy.xBank.51
MAXmalware (ai score=99)
MalwarebytesMachineLearning/Anomalous.95%
PandaGeneric Malware
RisingTrojan.Spy.Banker.GEN (CLOUD)
YandexTrojan.GenAsa!s0YLB1Y22Xg
IkarusTrojan-Spy.Win32.Banker
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/DelpBanc.A!tr.pws
AVGWin32:Banker-LKS [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/Spy.Banker.OWM?

Win32/Spy.Banker.OWM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment