Malware

About “Win32:Banker-GFZ [Trj]” infection

Malware Removal

The Win32:Banker-GFZ [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Banker-GFZ [Trj] virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory

How to determine Win32:Banker-GFZ [Trj]?


File Info:

name: 502D631E2601ED38B273.mlw
path: /opt/CAPEv2/storage/binaries/ecc008740ae1171281b9a8f19f49e982505f80982ae9dbb841baaf816530b95c
crc32: E856AA9A
md5: 502d631e2601ed38b27397389868a06d
sha1: 4ab2e6b5a5ebc98ccf739027ebd455ad5383ee21
sha256: ecc008740ae1171281b9a8f19f49e982505f80982ae9dbb841baaf816530b95c
sha512: b4aa99a6141f38c8f8c746f42b506a602ffa59ac45fdb3803604ba5424b203171f6551ef100cc59931c22acad1094e2c9c9570c44e9d0fcce1dd197cca96fe92
ssdeep: 12288:vTG2rrmIHVhub+R07FrBnuqH2X9xoVgHXSp:LFXmIH2b+2R5uqmXoec
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146B49F22F2D14537D1372B749D2BC1AD9835BF103E68A8467BE86D4C4F3E781392A1A7
sha3_384: 6f549b4604ada2de6f4d6580e096b0da8140450f2a2fb3756b17237af32a84e305eae38214b9f3bee58cd1fc52a78077
ep_bytes: 558becb9130000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32:Banker-GFZ [Trj] also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanWin32.Induc.A
CMCVirus.Win32.Induct.1!O
CAT-QuickHealW32.Induc.A
SkyhighBehavesLike.Win32.Generic.hh
Cylanceunsafe
ZillyaVirus.Induc.Win32.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaVirus:Win32/Induc.4c18c66f
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.e2601e
BitDefenderThetaAI:FileInfector.CFA710080D
VirITTrojan.Win32.Agent.E
SymantecW32.Induc.A
Elasticmalicious (high confidence)
ESET-NOD32Win32/Induc
APEXMalicious
TrendMicro-HouseCallBKDR_DEALFA.A
ClamAVWin.Virus.Induc-2
KasperskyVirus.Win32.Induc.b
BitDefenderWin32.Induc.A
NANO-AntivirusVirus.Win32.Induc.dffkeg
AvastWin32:Banker-GFZ [Trj]
TencentVirus.Win32.Indcu.A.200014
EmsisoftWin32.Induc.A (B)
BaiduWin32.Virus.Induc.a
F-SecureMalware.W32/Induc.blr
DrWebTrojan.PWS.VisStud.12
VIPREWin32.Induc.A
TrendMicroBKDR_DEALFA.A
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.502d631e2601ed38
SophosW32/Induc-A
IkarusVirus.Induc
JiangminWin32/Induc.a
GoogleDetected
AviraW32/Induc.blr
VaristW32/Induc.A.gen!Eldorado
Antiy-AVLVirus/Win32.Induc.b
KingsoftWin32.Induc.b.820224
MicrosoftTrojan:Win32/Modphip.A
XcitiumVirus.Win32.Induc.A0@1q1u4b
ArcabitWin32.Induc.A
ViRobotWin32.Induc.A
ZoneAlarmVirus.Win32.Induc.b
GDataWin32.Virus.Induct.A
CynetMalicious (score: 100)
AhnLab-V3Win32/Induc
McAfeeBackDoor-EAD
MAXmalware (ai score=100)
VBA32Virus.Win32.Induc.c
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
RisingVirus.Induc!1.9B53 (CLASSIC)
YandexTrojan.GenAsa!rVcEzkSOHgo
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Induc.A
FortinetW32/Nussamoc.A!tr
AVGWin32:Banker-GFZ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirus:Win/Induc.SysConst

How to remove Win32:Banker-GFZ [Trj]?

Win32:Banker-GFZ [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment