Trojan

Should I remove “Trojan-Banker.Win32.RTM.eph”?

Malware Removal

The Trojan-Banker.Win32.RTM.eph is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.eph virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.eph?


File Info:

crc32: 32F3ECDF
md5: 11ad3a31b69cef0cf3a85d47f10d0d71
name: 11AD3A31B69CEF0CF3A85D47F10D0D71.mlw
sha1: de4da9cb9f3abda55b6c4f3dfe9f5fda4e807441
sha256: 3a3b7caea242090de3f5e30612ac89d0c2c4e2c0e5e535d8955dcd137e09fc63
sha512: e6de59f803da94ebbc3106851a6b79d7a6acd586394ab9bad3c6619f28f79a8cbb0ee5b81163967c5ec8716db676738d01ee22a9d5a45542b8e797a164a13dd9
ssdeep: 3072:oZxPXWHms5JbMUEy69jqQ4Cb/H/4mi84tgVchKfHJqWuZ:ovXWHm3UErOQHz/4IHfp
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2003-2016 Glarysoft Ltd
InternalName: FileEncrypt.exe
FileVersion: 5, 0, 0, 35
CompanyName: Glarysoft Ltd
ProductName: Glary Utilities
ProductVersion: 5.0.0.1
FileDescription: File Encrypter and Decrypter
OriginalFilename: FileEncrypt.exe
Translation: 0x0804 0x03a8

Trojan-Banker.Win32.RTM.eph also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44839466
FireEyeGeneric.mg.11ad3a31b69cef0c
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.44839466
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan-Banker.Win32.RTM.eph
RisingTrojan.Kryptik!8.8 (TFE:5:67eOwHUbRhE)
Ad-AwareTrojan.GenericKD.44839466
EmsisoftTrojan.GenericKD.44839466 (B)
F-SecureHeuristic.HEUR/AGEN.1139560
DrWebTrojan.Inject4.6112
McAfee-GW-EditionBehavesLike.Win32.Dropper.vt
SophosML/PE-A + Mal/EncPk-APV
AviraHEUR/AGEN.1139560
MAXmalware (ai score=88)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.AVP!MTB
ArcabitTrojan.Generic.D2AC322A
ZoneAlarmTrojan-Banker.Win32.RTM.eph
GDataWin32.Trojan.Kryptik.KRRWOV
CynetMalicious (score: 100)
McAfeeGenericRXMV-OD!11AD3A31B69C
VBA32BScope.Trojan.Encoder
ESET-NOD32a variant of Win32/GenKryptik.EXVO
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_79%
FortinetW32/Kryptik.HDNN!tr
BitDefenderThetaGen:NN.ZedlaF.34670.eM8@aKeDa2fj
Qihoo-360HEUR/QVM40.1.B8AB.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.eph?

Trojan-Banker.Win32.RTM.eph removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment