Spy

About “Win32/Spy.Banker.QYO” infection

Malware Removal

The Win32/Spy.Banker.QYO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Banker.QYO virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory

How to determine Win32/Spy.Banker.QYO?


File Info:

name: FFD0F8998636EEBFDF3B.mlw
path: /opt/CAPEv2/storage/binaries/6f96de652c440b79685f012147a8b94915189f37739f91ceab72ad5422829057
crc32: 112B8991
md5: ffd0f8998636eebfdf3bcc292146f4f4
sha1: 0f6d26b751fb22ca5e142730039574898a4f579a
sha256: 6f96de652c440b79685f012147a8b94915189f37739f91ceab72ad5422829057
sha512: 84f504a0ebb9b61736a5b7a5d7c99976c68d14a7d35bd69e18c14687fe6476716908e9ea547c592747178b8df6a720e2ccad40b3f1edcdfad84007ef6a0c636e
ssdeep: 12288:dNhpe8VoTMEqN1tKlOB6mIkCohj16hhQs:DH3V3Eqj01IH2hj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F4B48D62F2D18537D1672B349C2B91A99C36BF103E2CB9467BE81C0C5F397C1792A1E6
sha3_384: c62504e6aca4f2b87c2ef26664c8e98f05d4db4571f5a9bb9b27d9766d5329f036855f0ec5acda3e254ed987d1d8602b
ep_bytes: 558becb9130000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Spy.Banker.QYO also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.UserStartup.FGW@aqYmf4f
ClamAVWin.Malware.Graftor-6838241-0
McAfeeGeneric PWS.sr
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Riodrv.Win32.174
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.98636e
BitDefenderThetaAI:Packer.92DAF4B119
VirITTrojan.Win32.Riodrv.AKL
CyrenW32/Modphip.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Banker.QYO
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Riodrv.aqv
BitDefenderGen:Trojan.UserStartup.FGW@aqYmf4f
NANO-AntivirusTrojan.Win32.Agent.balvf
TencentMalware.Win32.Gencirc.10b0a70b
TACHYONTrojan/W32.DP-Agent.510464.L
EmsisoftGen:Trojan.UserStartup.FGW@aqYmf4f (B)
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.PWS.Banker.28819
VIPREGen:Trojan.UserStartup.FGW@aqYmf4f
TrendMicroTSPY_BANKER.SMQO
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.ffd0f8998636eebf
SophosML/PE-A
IkarusTrojan-PWS.Win32.Riodrv
GDataGen:Trojan.UserStartup.FGW@aqYmf4f
JiangminBackdoor/Delf.kys
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[PSW]/Win32.Riodrv
XcitiumTrojWare.Win32.PSW.Riodrv.~G@1hyo18
ArcabitTrojan.UserStartup.EE25CE
ZoneAlarmTrojan-PSW.Win32.Riodrv.aqv
MicrosoftTrojan:Win32/Modphip.A
GoogleDetected
AhnLab-V3Trojan/Win32.Riodrv.R7514
Acronissuspicious
VBA32Win32.Trojan.Dropper.Heur
ALYacGen:Trojan.UserStartup.FGW@aqYmf4f
MAXmalware (ai score=89)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTSPY_BANKER.SMQO
RisingSpyware.Banker!8.8D (TFE:4:HT31vDDDceG)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Nussamoc.A!tr
AVGWin32:Banker-GFZ [Trj]
AvastWin32:Banker-GFZ [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Spy.Banker.QYO?

Win32/Spy.Banker.QYO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment