Malware

Win32:Bancos-MS [Trj] information

Malware Removal

The Win32:Bancos-MS [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Bancos-MS [Trj] virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32:Bancos-MS [Trj]?


File Info:

crc32: 404518E1
md5: 1554d24cf31ef409fac0963bc6ecd755
name: 1554D24CF31EF409FAC0963BC6ECD755.mlw
sha1: e1c16575fe3a95a1f749006e0927d705785b7830
sha256: 047cd4a724afbf3b24107e170e5137bbd9e3c882b509abe6e26959249c530ca2
sha512: bd8b3960063a42a4234e5fe769ff078e6b84e7d4a4bfacbb0a35c7a66f9c751dad4db5d1756263c520380d00abb2532699560992c383fccb059fb6939d7f3785
ssdeep: 3072:o+lz0YQxlKEkDDgOSQ1qrCTMOeTBRkVs7PEGj:LlJK/kD0O5yCTMjV28sy
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Microsoft Corporation
InternalName: kernelsNT
FileVersion: 3.00
CompanyName: Microsoft Corporation
LegalTrademarks: Microsoft Corporation
Comments: kernelNT
ProductName: kernelNT
ProductVersion: 3.00
FileDescription: kernelNT.exe
OriginalFilename: kernelsNT.exe

Win32:Bancos-MS [Trj] also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005376ae1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Bancos.207
CynetMalicious (score: 99)
ALYacDropped:Trojan.Banker.VB.AB
CylanceUnsafe
ZillyaTrojan.Bancos.Win32.23339
SangforTrojan.Win32.Bancos.ha
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojanBanker:Win32/Bancos.40a7fa6e
K7GWTrojan ( 005376ae1 )
Cybereasonmalicious.cf31ef
BaiduWin32.Trojan.Bancos.a
CyrenW32/Threat-SysVenFakP-based!Max
SymantecInfostealer.Bancos
ESET-NOD32Win32/Spy.Bancos.U
APEXMalicious
AvastWin32:Bancos-MS [Trj]
ClamAVWin.Spyware.Banker-201
KasperskyTrojan-Banker.Win32.Bancos.ha
BitDefenderDropped:Trojan.Banker.VB.AB
NANO-AntivirusTrojan.Win32.Banker.eprp
ViRobotTrojan.Win32.Bancos.122880.O
MicroWorld-eScanDropped:Trojan.Banker.VB.AB
Ad-AwareDropped:Trojan.Banker.VB.AB
SophosML/PE-A + Troj/Bancos-RO
ComodoTrojWare.Win32.Spy.Bancos.ha_dam0@1n5j4q
BitDefenderThetaGen:NN.ZevbaF.34790.hi0fam04p8ji
TrendMicroTROJ_BANCOS.HA
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
FireEyeGeneric.mg.1554d24cf31ef409
EmsisoftDropped:Trojan.Banker.VB.AB (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Bancos.ha.dam
Antiy-AVLTrojan/Generic.ASBOL.872
MicrosoftTrojan:Win32/Ditertag.A
ZoneAlarmTrojan-Banker.Win32.Bancos.ha
GDataDropped:Trojan.Banker.VB.AB
TACHYONTrojan-Spy/W32.Banker.122880.I
AhnLab-V3Trojan/Win32.Bancos.R148139
Acronissuspicious
McAfeePWS-Banker.gen.h
MAXmalware (ai score=81)
MalwarebytesMalware.AI.1122021668
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_BANCOS.HA
RisingTrojan.Spy.Banbra.onq (CLASSIC)
YandexTrojan.GenAsa!cFeEC+mOf6w
IkarusTrojan-Spy.Win32.Bancos.ha
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bancos.HA!tr
AVGWin32:Bancos-MS [Trj]
Paloaltogeneric.ml

How to remove Win32:Bancos-MS [Trj]?

Win32:Bancos-MS [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment