Trojan

Trojan-Banker.Win32.RTM.fqp malicious file

Malware Removal

The Trojan-Banker.Win32.RTM.fqp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.fqp virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup

How to determine Trojan-Banker.Win32.RTM.fqp?


File Info:

crc32: 1F3E4E2B
md5: 6ca1736c7de72e27e9631894e398b3c3
name: 6CA1736C7DE72E27E9631894E398B3C3.mlw
sha1: 9842e5eecc282aef523fb4054059ee2684d19fcc
sha256: c14f881e454bb9e7c6d48171a24a27bf6f601f2d24a600612d7ef5a00bca899f
sha512: ce3144fbf57f8048707e7e57c0e11346866996fccbd5738e53299339d264df69b793644b8ae8cb1dfed11f0a26e3c875da9c42c282cac93fe099bfc97be48d9a
ssdeep: 49152:+KF/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb:
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2014 AVG Technologies CZ, s.r.o.
InternalName: AvDump32
FileVersion: 17.3.3443.0
CompanyName: AVG Technologies CZ, s.r.o.
ProductName: AVG Internet Security System
ProductVersion: 17.3.3443.0
FileDescription: AVG Dump Process
OriginalFilename: AvDump32.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.fqp also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.6278
MicroWorld-eScanGen:Variant.Zusy.356932
FireEyeGeneric.mg.6ca1736c7de72e27
McAfeeGenericRXMZ-SU!6CA1736C7DE7
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Zusy.356932
K7GWTrojan ( 00574aa51 )
K7AntiVirusTrojan ( 00574aa51 )
BitDefenderThetaGen:NN.ZedlaF.34700.c68@aeK2ELei
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0RLG20
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Trojan.Generic-9808189-0
KasperskyTrojan-Banker.Win32.RTM.fqp
AegisLabHacktool.Win32.Krap.lKMc
RisingTrojan.Kryptik!1.CFFC (CLASSIC)
Ad-AwareGen:Variant.Zusy.356932
EmsisoftTrojan.Crypt (A)
McAfee-GW-EditionBehavesLike.Win32.Dropper.vt
SophosML/PE-A + Mal/EncPk-APV
SentinelOneStatic AI – Malicious PE
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Ymacco.AAC1
GridinsoftTrojan.Win32.Kryptik.oa!s12
ArcabitTrojan.Zusy.D57244
ZoneAlarmTrojan-Banker.Win32.RTM.fqp
GDataGen:Variant.Zusy.356932
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R358128
VBA32BScope.Backdoor.Vawtrak
ALYacGen:Variant.Graftor.868310
MAXmalware (ai score=85)
MalwarebytesBackdoor.Qbot
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HIGG
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM39.1.F81F.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.fqp?

Trojan-Banker.Win32.RTM.fqp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment