Trojan

Trojan-Banker.Win32.RTM.eji removal tips

Malware Removal

The Trojan-Banker.Win32.RTM.eji is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.eji virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A process attempted to delay the analysis task by a long amount of time.
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.eji?


File Info:

crc32: 4F29C64B
md5: 53b8f339e07ad1234d81f3aa710532b3
name: 53B8F339E07AD1234D81F3AA710532B3.mlw
sha1: 42c074153239cbe58d45a29e802463b0a8f66750
sha256: cb3b743baca198315760e6c0ac6a1a7ddce5111a835ad47f268e48a8623b3160
sha512: d08c6ffe179585507f8ae8b4f1550583bef5c8201cd9730b5dcdfffe42f53e706a40f798a1e335133b7bc3532766d5dd119f119d80aa27150e3b466a83d5e34d
ssdeep: 12288:G9KeV/FDMBmC888888888888W88888888888:G9KeV/F4B
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxa92005-2015 IObit
InternalName:
FileVersion: 8.0.0.1327
CompanyName: IObit
LegalTrademarks: IObit
Comments:
ProductName: Initialization Program
ProductVersion: 8.0.0.0
FileDescription: Advanced SystemCare Ultimate
OriginalFilename:
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.RTM.eji also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44817575
FireEyeGeneric.mg.53b8f339e07ad123
McAfeeGenericRXMV-GQ!53B8F339E07A
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.44817575
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderThetaGen:NN.ZedlaF.34670.gI8@a4sOuApj
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHZE
APEXMalicious
ClamAVWin.Malware.Emotet-7352065-0
KasperskyTrojan-Banker.Win32.RTM.eji
Ad-AwareTrojan.GenericKD.44817575
SophosML/PE-A + Mal/EncPk-APV
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.44817575 (B)
MAXmalware (ai score=88)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
ArcabitTrojan.Generic.D2ABDCA7
ZoneAlarmTrojan-Banker.Win32.RTM.eji
GDataTrojan.GenericKD.44817575
CynetMalicious (score: 100)
VBA32BScope.Trojan.Encoder
MalwarebytesPUP.Optional.AdvancedSystemCare
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HDNN!tr
Qihoo-360HEUR/QVM40.1.B377.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.eji?

Trojan-Banker.Win32.RTM.eji removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment