Threat Database Trojans Trojan.Banker.LA

Trojan.Banker.LA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 231
First Seen: January 16, 2013
Last Seen: March 9, 2026
OS(es) Affected: Windows

The detection of Trojan.Banker.LA on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, guidance on how to remove it from your system.

What Is Trojan.Banker.LA?

Trojan.Banker.LA is identified as a Trojan-type threat, which is a broad category of malware designed to allow unauthorized access to a computer system. Trojans are often disguised as legitimate software and can cause significant harm by stealing sensitive information, installing additional malware, or providing a backdoor for remote access. The name "Trojan.Banker.LA" suggests it might be focused on banking or financial information theft, but without specific details, it's crucial to approach removal with a broad strategy to ensure all potential aspects of the threat are addressed.

How Trojan.Banker.LA Operates

Trojan.Banker.LA, like other Trojans, operates by exploiting vulnerabilities in software or human behavior to infect a system. It might spread through phishing emails, infected software downloads, or exploited vulnerabilities in operating systems or applications. Once inside, it can execute a variety of malicious actions, potentially including data theft, keystroke logging, or the installation of additional malware. The specific operations of Trojan.Banker.LA would depend on its design and the intentions of its creators, but the end goal is typically financial gain or the expansion of a botnet for further malicious activities.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common signs include unusual system behavior, such as unexpected pop-ups, slow performance, or programs opening and closing on their own. Additionally, if you notice unauthorized transactions or changes in your financial accounts, it could be a sign that your system is infected with a banking Trojan like Trojan.Banker.LA. Other symptoms might include unfamiliar programs or toolbars in your browser, changes in your system settings, or an increase in spam emails being sent from your accounts.

How to Remove Trojan.Banker.LA

  1. Enter Safe Mode with Networking: This will limit the malware's ability to interfere with the removal process. Restart your computer and press the key to access the boot menu (this varies by manufacturer but is often F8, F12, or Del). Select Safe Mode with Networking to proceed.
  2. Conduct a Full Scan with a Reputable Tool: Utilize a trusted anti-malware program, such as SpyHunter, to perform a full scan of your system. This can help identify and remove all components of the Trojan.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove anything that seems unfamiliar or was installed around the time you suspect the infection occurred.
  4. Reset Your Browsers: Resetting browsers like Chrome, Firefox, or Edge to their default settings can remove any malicious extensions or settings changes made by the Trojan. You can usually find this option in the browser's settings or preferences menu.
  5. Reboot and Re-scan: After completing the above steps, restart your computer in normal mode and perform another full scan with your anti-malware tool to ensure all threats have been removed.

Conclusion

Removing Trojan.Banker.LA from your system requires careful and thorough action to ensure all components of the malware are eliminated. By following the steps outlined in this report and maintaining vigilance in your online activities, you can significantly reduce the risk of future infections. Regularly updating your software, using strong antivirus programs, and being cautious with emails and downloads are key practices in protecting your digital security. If you're unsure about any part of the removal process, consider consulting with a professional to ensure your system is completely secure.

Analysis Report

General information

Family Name: Trojan.Banker.LA
Signature status: No Signature

Known Samples

MD5: e945dffe28203982037fb326780f67f0
SHA1: 5c6bc977b740f60906fb9d35bbaef2f7aecc0fba
SHA256: 70B0D41D03E33DA4E28011773039923B7C21104F17B556038C4E16EC5F17FE38
File Size: 1.47 MB, 1469952 bytes
MD5: 9516530c41546bd1619eb7e8a8c5f53b
SHA1: 2fed10e5a93046db1872d5bd05d5f27f6d7fc14f
SHA256: 2F0A28548228D2DDECAE349049E0B7AFDE2F5EFE9DAD2BBAD17F8C5ACB420DFB
File Size: 812.54 KB, 812544 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name (주)이지닉스
File Description AnyCall PCManager Plus Upgrade
File Version
  • 1.1.16.329
  • 1.0.3.0
Internal Name AnyCall PCManager Plus Upgrade
Original Filename PCManagerPlus.exe
Product Version 1.0.0.0

File Traits

  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 2,568
Potentially Malicious Blocks: 6
Whitelisted Blocks: 2,455
Unknown Blocks: 107

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Banker.TH
  • Injector.DGB
  • Injector.GDSA
  • Injector.KFAD
  • Injector.KI
Show More
  • Injector.KZK
  • Injector.KZP

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\samsung\anycallmanager::useableflag TRUE RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\general::install date 2025/10/22 RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::autoexec RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::pcmanagerplus c:\users\user\downloads\PCManagerPlus.exe /AUTOEXEC RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::autologin 0 RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::automsg 1 RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::desktopicon 1 RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::namephoneshow 0 RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::enablemsgwinpos 0 RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::enablemsgwindelay 1 RegNtPreCreateKey
Show More
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::valuemsgwinpos 0 RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::valuemsgwindelay RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::companycode 284 RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::photopath RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::skin PMP_SKIN_1.dll RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::leftposition RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::topposition RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::chatsound 1 RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::pwver 385 RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\general::version 1 RegNtPreCreateKey
HKLM\software\wow6432node\samsung\anycallmanager\mini\config::autoexec 0 RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSAStartup

Related Posts

Trending

Most Viewed

Loading...