Spy

Win32/Spy.Banker.UUJ malicious file

Malware Removal

The Win32/Spy.Banker.UUJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Banker.UUJ virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Spy.Banker.UUJ?


File Info:

name: 8640AF68B2D110F1DE0E.mlw
path: /opt/CAPEv2/storage/binaries/8ddcf4dea0b4dc413394d3f00c4297128e9cd7f22f6a8d8f71a05ea1a93274a5
crc32: 0EF4A65A
md5: 8640af68b2d110f1de0e754d99395586
sha1: 0b875bc6af3a6368d7b270f5c20d486c253fede2
sha256: 8ddcf4dea0b4dc413394d3f00c4297128e9cd7f22f6a8d8f71a05ea1a93274a5
sha512: 1b9fff7ac4242ff3a28a8d6cca02ad5c5d2564eee6d62ba5cbe22ee91aeb37b112f31caafd898bd08a77039ef5f3646fcc82e684f71c0efb647fe731fb081900
ssdeep: 24576:XWKAH9j5z7WL0T2r1MAW4CwqLuTe/4HNbSnIHNUjnFcm3fVaUA9XaMrZdgelt81f:XWKG/02AXT0Xv4tHzg1QY4MXZJUFK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C7E5AE32F242C467D56359388C5B92A84528BF551E78A86F3BE9BE8C8F377837C14187
sha3_384: d12699f3b82702863b0ecd5b772aac32f0c7afad60f01644d33f76485eefd8a6554bae875b7bda85d31fe954a33bbee1
ep_bytes: 558bec83c4f053b8705e5800e81f08e8
timestamp: 2001-08-17 20:52:32

Version Info:

0: [No Data]

Win32/Spy.Banker.UUJ also known as:

LionicTrojan.Win32.Banker.7!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.7kW@tPO8BmoPh
FireEyeGeneric.mg.8640af68b2d110f1
McAfeeArtemis!8640AF68B2D1
CylanceUnsafe
ZillyaTrojan.Banker.Win32.51362
SangforTrojan.Win32.Save.a
Cybereasonmalicious.8b2d11
ArcabitTrojan.Heur.ECD6E3
BitDefenderThetaAI:Packer.AB30A6C11D
VirITTrojan.Win32.Banker6.KFE
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Spy.Banker.UUJ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Generic-7663331-0
KasperskyTrojan-Banker.Win32.Banker.bhpl
BitDefenderGen:Trojan.Heur.7kW@tPO8BmoPh
NANO-AntivirusTrojan.Win32.Banker.oepzx
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan-Banker.Banker.Wdkl
Ad-AwareGen:Trojan.Heur.7kW@tPO8BmoPh
EmsisoftGen:Trojan.Heur.7kW@tPO8BmoPh (B)
ComodoMalware@#2zhe14t16r8lq
VIPREGen:Trojan.Heur.7kW@tPO8BmoPh
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.vh
Trapminesuspicious.low.ml.score
SophosMal/Emogen-T
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.CFI.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.2F
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Trojan.Heur.7kW@tPO8BmoPh
CynetMalicious (score: 100)
Acronissuspicious
VBA32TrojanBanker.Banker
ALYacGen:Trojan.Heur.7kW@tPO8BmoPh
MalwarebytesMalware.Heuristic.1006
RisingMalware.Undefined!8.C (TFE:5:7szXA13vxUC)
YandexTrojan.PWS.Banker!RFnfSPtkX0M
IkarusTrojan-Downloader.Win32.Homa
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Banker.BHPL!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Spy.Banker.UUJ?

Win32/Spy.Banker.UUJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment