Trojan

Trojan-Banker.Win32.RTM.epi removal tips

Malware Removal

The Trojan-Banker.Win32.RTM.epi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.epi virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.epi?


File Info:

crc32: AA87DABB
md5: da129b9453bccd0d37d53926c6c8c158
name: DA129B9453BCCD0D37D53926C6C8C158.mlw
sha1: e583f42b5ae79df067b1319377a740430d99aeb4
sha256: 5e4c30d9ddfc6aa53ec18d514e70739cf1096c874b151281738819f43c73b389
sha512: d75aa5f6482366ca07d0dbad3e4144825c24231bf10d0dca36cd86cd6b5d97f6eb5971d385d04fdd4bd3c2c56da4de95e0111f929a2b09ff5210af3e75ecb003
ssdeep: 3072:/ZxPXWHms5JbMUEy69jqQ4Cb/H/4mi84tgVchKfHJSWuZ:/vXWHm3UErOQHz/4IHfp
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2003-2016 Glarysoft Ltd
InternalName: FileEncrypt.exe
FileVersion: 5, 0, 0, 35
CompanyName: Glarysoft Ltd
ProductName: Glary Utilities
ProductVersion: 5.0.0.1
FileDescription: File Encrypter and Decrypter
OriginalFilename: FileEncrypt.exe
Translation: 0x0804 0x03a8

Trojan-Banker.Win32.RTM.epi also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44840013
FireEyeGeneric.mg.da129b9453bccd0d
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.44840013
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderThetaGen:NN.ZedlaF.34670.eM8@amLQi7gj
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan-Banker.Win32.RTM.epi
RisingTrojan.Kryptik!8.8 (TFE:5:67eOwHUbRhE)
Ad-AwareTrojan.GenericKD.44840013
EmsisoftTrojan.GenericKD.44840013 (B)
F-SecureHeuristic.HEUR/AGEN.1139560
DrWebTrojan.Inject4.6112
McAfee-GW-EditionBehavesLike.Win32.Dropper.vt
SophosML/PE-A + Mal/EncPk-APV
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1139560
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.AVP!MTB
ArcabitTrojan.Generic.D2AC344D
ZoneAlarmTrojan-Banker.Win32.RTM.epi
GDataWin32.Trojan.Kryptik.WC8GI0
CynetMalicious (score: 100)
McAfeeGenericRXMV-OD!DA129B9453BC
VBA32BScope.Trojan.Encoder
ESET-NOD32a variant of Win32/GenKryptik.EXVO
eGambitUnsafe.AI_Score_79%
FortinetW32/Kryptik.HDNN!tr
Paloaltogeneric.ml
Qihoo-360HEUR/QVM40.1.B8AB.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.epi?

Trojan-Banker.Win32.RTM.epi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment