Spy

Win32/Spy.Banker.ZGJ (file analysis)

Malware Removal

The Win32/Spy.Banker.ZGJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Banker.ZGJ virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Spy.Banker.ZGJ?


File Info:

name: EC3A9D37844744BEC58E.mlw
path: /opt/CAPEv2/storage/binaries/e5961f3ce330e9fda52d5305b2b7ec8dc55396a37527a49eb5458b54cb592211
crc32: 1772B943
md5: ec3a9d37844744bec58e7ad8122245f1
sha1: 0bbb9a4cb96112ab9ccff93809e8b384eba0acda
sha256: e5961f3ce330e9fda52d5305b2b7ec8dc55396a37527a49eb5458b54cb592211
sha512: a66babdc8b6a5d6dea03268084a4a7032586581c3fffa3df153a814578a7cdfddeed8a35e52440d25a533f24475486b2d9caa7bbc43e1163277a3ff13d45d5a5
ssdeep: 24576:y43ywLxE5MjMLwsOCGEWyHDuxT3nilHYl3ukn:y43VQ+CG/MDkT3nilqu4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188357D21A6907C73C5E21E38DC3BB7699C3DBE106D28A4466BE53E0C7E762413D25E93
sha3_384: e2dc4fe78dcb6f25a5aade115d2757dab5ef132ee6a0578e06b62caa2497623a65794f2d1c529b89224cb8e9a5949010
ep_bytes: 558bec83c4f053b8146b4a00e847f3f5
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Spy.Banker.ZGJ also known as:

LionicHeuristic.File.Generic.00×1!p
MicroWorld-eScanGen:Trojan.Heur.eHW@tz7uLXoGd
FireEyeGeneric.mg.ec3a9d37844744be
McAfeeArtemis!EC3A9D378447
CylanceUnsafe
SangforSpyware.Win32.Agent.Vxdq
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanSpy:Win32/Banker.bf12513d
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.784474
BitDefenderThetaAI:Packer.DD4EAADC1D
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Banker.ZGJ
APEXMalicious
TrendMicro-HouseCallTROJ_SPNR.14A813
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Trojan.Heur.eHW@tz7uLXoGd
NANO-AntivirusTrojan.Win32.Gypikonbased.bgyyei
AvastWin32:Malware-gen
TencentWin32.Trojan.Spy.Rsmw
Ad-AwareGen:Trojan.Heur.eHW@tz7uLXoGd
SophosMal/DelpBanc-A
ComodoMalware@#310d57cfly1y8
VIPREGen:Trojan.Heur.eHW@tz7uLXoGd
TrendMicroTROJ_SPNR.14A813
McAfee-GW-EditionBehavesLike.Win32.Worm.th
Trapminemalicious.moderate.ml.score
EmsisoftGen:Trojan.Heur.eHW@tz7uLXoGd (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Trojan.Heur.eHW@tz7uLXoGd
GoogleDetected
AviraTR/Spy.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Heur.KVM011.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Banker.C78867
VBA32BScope.TrojanSpy.Banker
ALYacGen:Trojan.Heur.eHW@tz7uLXoGd
MalwarebytesGeneric.Trojan.Banker.DDS
RisingTrojan.Ymacco!8.11BE1 (TFE:4:HozmLnVodIE)
IkarusPacked.Win32.Katusha
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/DelpBanc.A!tr
AVGWin32:Malware-gen
PandaTrj/Chgt.AB
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Spy.Banker.ZGJ?

Win32/Spy.Banker.ZGJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment