Trojan

Trojan-Banker.Win32.RTM.dko removal instruction

Malware Removal

The Trojan-Banker.Win32.RTM.dko is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.dko virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.dko?


File Info:

crc32: 0DD266AF
md5: 9383bdf92442dc0bd472559a310606e8
name: 9383BDF92442DC0BD472559A310606E8.mlw
sha1: 84fda7c27406cd59b72f37ec877b88001b4bff27
sha256: bf85b68e00a925fe4cb19530d5fa1a02dc566ca07f22151abfa93a8194465c8d
sha512: e86ac5e1e7fc9e89c192e55d1a022c67786f9f74e0ba5df096e2dff7803be31b567aa69e1f31bd9662bb935b2cae6e71fe4cba3aaf9642885207ef1b372a3b56
ssdeep: 3072:w8qk4FRozXKEI7jQC5VrmpL2zqpOAZpDpOKfbG/lURhiOPe8IYtuho:w8qkyT7jzGl22pJZJeSh
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2007, 2008, 2009, 2010, 2011, 2012 Jakub Wilk
FileDescription: PDF to DjVu converter
FileVersion: 0.7.14
Comments: This package is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; version 2 dated June, 1991.
ProductName: pdf2djvu 0.7.14 (DjVuLibre 3.5.25, poppler 0.18.4, GNOME XSLT 1.1.26, GNOME XML 2.7.8)
Translation: 0x0409 0x0000

Trojan-Banker.Win32.RTM.dko also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44650458
FireEyeGeneric.mg.9383bdf92442dc0b
McAfeeGenericRXMS-RZ!9383BDF92442
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.44650458
APEXMalicious
KasperskyTrojan-Banker.Win32.RTM.dko
RisingTrojan.GenKryptik!8.AA55 (TFE:4:XWEI88FDE4T)
Ad-AwareTrojan.GenericKD.44650458
EmsisoftTrojan.GenericKD.44650458 (B)
DrWebTrojan.Inject4.5734
McAfee-GW-EditionArtemis!Trojan
SophosMal/EncPk-APV
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftRansom.Win32.Wacatac.dd!n
ArcabitTrojan.Generic.D2A94FDA
ZoneAlarmTrojan-Banker.Win32.RTM.dko
GDataTrojan.GenericKD.44650458
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZedlaF.34658.8w8@aqCUW5ji
ALYacTrojan.GenericKD.44650458
VBA32BScope.Trojan.Ditertag
PandaTrj/Agent.DLL
ESET-NOD32a variant of Win32/Kryptik.HHSR
FortinetW32/Kryptik.HDNN!tr
Qihoo-360HEUR/QVM40.1.8688.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.dko?

Trojan-Banker.Win32.RTM.dko removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment