Trojan

Trojan-Banker.Win32.RTM.fqk removal instruction

Malware Removal

The Trojan-Banker.Win32.RTM.fqk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.fqk virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Executed a process and injected code into it, probably while unpacking

How to determine Trojan-Banker.Win32.RTM.fqk?


File Info:

crc32: 812533C6
md5: da87a1768539814a01495b79073acce9
name: DA87A1768539814A01495B79073ACCE9.mlw
sha1: 44185496958684ca40d114b8d163b3479a239202
sha256: 9f23d893c6be55609c3d19460044166469ede43e57e93e961c10593155d7bd0c
sha512: 6c02883eca25f0cbe53ff3902b6d306c09d1a112307398a03bf5614c1fa9ee70e84dc6e3551e9ad7635e5183799e39bd0c527595461c23f3f7f04a5c413943b9
ssdeep: 49152:5KM/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb:
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 360.cn Inc. All Rights Reserved.
InternalName: 360DeskAna.exe
FileVersion: 1, 0, 0, 1018
CompanyName: 360.cn
ProductName: 360????
ProductVersion: 1, 0, 0, 1018
FileDescription: 360???? ??????????
OriginalFilename: 360DeskAna.exe
Translation: 0x0804 0x04b0

Trojan-Banker.Win32.RTM.fqk also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.6227
MicroWorld-eScanTrojan.GenericKD.35705282
FireEyeGeneric.mg.da87a1768539814a
Qihoo-360HEUR/QVM39.1.EFA0.Malware.Gen
ALYacTrojan.GenericKD.35705282
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005749c51 )
K7AntiVirusTrojan ( 005749c51 )
ArcabitTrojan.Generic.D220D1C2
BitDefenderThetaGen:NN.ZedlaF.34688.d28@aKesl9dj
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIEA
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Trojan.Generic-9808189-0
KasperskyTrojan-Banker.Win32.RTM.fqk
BitDefenderTrojan.GenericKD.35705282
RisingTrojan.Kryptik!1.CFFC (CLASSIC)
Ad-AwareTrojan.GenericKD.35705282
EmsisoftTrojan.GenericKD.35705282 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.vt
SophosML/PE-A + Mal/EncPk-APV
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
GridinsoftTrojan.Win32.Kryptik.oa!s11
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmTrojan-Banker.Win32.RTM.fqk
GDataWin32.Trojan.QBot.8P41LY
CynetMalicious (score: 100)
McAfeeGenericRXMZ-SU!DA87A1768539
VBA32BScope.Backdoor.Vawtrak
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
PandaTrj/GdSda.A

How to remove Trojan-Banker.Win32.RTM.fqk?

Trojan-Banker.Win32.RTM.fqk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment