Spy

Win32/Spy.Banker.VJ malicious file

Malware Removal

The Win32/Spy.Banker.VJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Banker.VJ virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Win32/Spy.Banker.VJ?


File Info:

name: C2592B38BE447F5AA453.mlw
path: /opt/CAPEv2/storage/binaries/50801b8cc17fd9bc259968b368ec63b25f98f1e6b3b046e0ad1f94626107326f
crc32: 384A9087
md5: c2592b38be447f5aa453d3fb9b0ec6dd
sha1: 5840f38ae3e49080375411fe5be65df725a1e989
sha256: 50801b8cc17fd9bc259968b368ec63b25f98f1e6b3b046e0ad1f94626107326f
sha512: b81d6e8e33fee0c5d4cc5d3f853ad83fb3e20fdf12cfb381aeb2fa6e127b15952800b676118aad628aab17e1e719752098dc6efc3734bab80c7f4c946d72f316
ssdeep: 98304:muZHBBBBBBBBcBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB0:mm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9062B6C7932B011D512163E3B199BD590EBAFCBEB07EB4624C53AC8DB732D47E14A12
sha3_384: 8a30f8f94f099b816856244eba739367f116f13106ece5c87c43719c3b474ed3d5b29478bf737e4e0851241cbd675611
ep_bytes: 558bec83c4f053b858104900e87b4bf7
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Spy.Banker.VJ also known as:

BkavW32.Common.22322A35
LionicTrojan.Win32.Banker.l755
AVGWin32:Agent-ALK [Trj]
MicroWorld-eScanGen:Trojan.SMTP-Mailer.QJW@auckP4dG
FireEyeGeneric.mg.c2592b38be447f5a
CAT-QuickHealTrojan.Banker.10032
SkyhighPWS-Banker.gen.t
ALYacGen:Trojan.SMTP-Mailer.QJW@auckP4dG
MalwarebytesBanker.Trojan.Stealer.DDS
ZillyaTrojan.Banker.Win32.33289
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Banker.4e26e0fc
K7GWSpyware ( 0055e3db1 )
K7AntiVirusSpyware ( 0055e3db1 )
BitDefenderThetaAI:Packer.394AA94B20
SymantecInfostealer.Banpaes
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Banker.VJ
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Trojan.Bancos-830
KasperskyHEUR:Trojan-Dropper.Win32.Sysn.gen
BitDefenderGen:Trojan.SMTP-Mailer.QJW@auckP4dG
NANO-AntivirusTrojan.Win32.Banker.vxhx
AvastWin32:Agent-ALK [Trj]
TencentMalware.Win32.Gencirc.13fef0b8
EmsisoftGen:Trojan.SMTP-Mailer.QJW@auckP4dG (B)
BaiduWin32.Trojan-Spy.Banker.a
F-SecureTrojan.TR/Spy.Banker.Gen
DrWebTrojan.PWS.Banker.based
VIPREGen:Trojan.SMTP-Mailer.QJW@auckP4dG
TrendMicroTROJ_BANKER.SMTX
Trapminesuspicious.low.ml.score
SophosTroj/Bancb-Fam
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.SMTP-Mailer.QJW@auckP4dG
JiangminTrojanSpy.Banker.gug
WebrootW32.InfoStealer.Bancos
VaristW32/Banker.D.gen!Eldorado
AviraTR/Spy.Banker.Gen
Antiy-AVLTrojan[Banker]/Win32.Banker
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.TrojanSpy.Banker.~AQL@4xjt1
ArcabitTrojan.SMTP-Mailer.E39C71
ViRobotTrojan.Win32.A.Banker.3833856.D
ZoneAlarmHEUR:Trojan-Dropper.Win32.Sysn.gen
MicrosoftTrojanSpy:Win32/Banker
GoogleDetected
AhnLab-V3Trojan/Win32.Banker.R11267
McAfeePWS-Banker.gen.t
MAXmalware (ai score=100)
VBA32BScope.Trojan.Cosmu
Cylanceunsafe
PandaTrj/Banker.ITS
TrendMicro-HouseCallTROJ_BANKER.SMTX
RisingSpyware.Banker!1.CEB7 (CLASSIC)
YandexTrojan.GenAsa!wrtWWMwOIAE
IkarusTrojan-Banker.Win32.Banz
MaxSecureTrojan.Malware.1385733.susgen
FortinetW32/Banker.BIG!tr.spy
Cybereasonmalicious.8be447
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/Banker.VJ

How to remove Win32/Spy.Banker.VJ?

Win32/Spy.Banker.VJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment