Trojan

Trojan-Banker.Win32.RTM.fyg removal

Malware Removal

The Trojan-Banker.Win32.RTM.fyg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.fyg virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup

How to determine Trojan-Banker.Win32.RTM.fyg?


File Info:

crc32: 78E708A1
md5: edf911ec756ea9669b94240c27b16a6b
name: EDF911EC756EA9669B94240C27B16A6B.mlw
sha1: e89a81a200a1704a5180a56adf685098c0d38a7a
sha256: 1c54c92bcc7c1c37be70229786ffc89996f9ef97f6e3038153525b983baf005d
sha512: 817b6362fbb33ee6303acf4dcbe2e0db467912f0025604a55efce9ef0b56d8956062a9d89d4543d9177646495dbafa44c47e3eb3d17548f37388ca0706c99ac5
ssdeep: 24576:FeRYe2+Ub9ENHvbyVfbWWbyHjaSabybbybvkblebRv:FeRL090EkC
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Slacker, Inc. 2006-2010.
InternalName: jukebox
FileVersion: 2.1.2370.0000
CompanyName: Slacker
ProductName: Slacker Software Player
ProductVersion: 2.1.2370.0000
FileDescription: Slacker Jukebox
OriginalFilename: slacker.jukebox.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.fyg also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.FAOU
FireEyeGeneric.mg.edf911ec756ea966
McAfeeGenericRXAA-AA!EDF911EC756E
CylanceUnsafe
AegisLabHacktool.Win32.Krap.lKMc
SangforMalware
BitDefenderTrojan.Agent.FAOU
K7GWBackdoor ( 00573a651 )
K7AntiVirusBackdoor ( 00573a651 )
CyrenW32/Kryptik.CSQ.gen!Eldorado
SymantecTrojan.Maltrec.TS
ESET-NOD32Win32/Qbot.CU
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyTrojan-Banker.Win32.RTM.fyg
Ad-AwareTrojan.Agent.FAOU
SophosML/PE-A + Mal/EncPk-APV
ComodoMalware@#18jjegu8ia8pn
DrWebBackDoor.Qbot.569
McAfee-GW-EditionArtemis!Trojan
EmsisoftMalCert.A (A)
IkarusTrojan.Qbot
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.V!cert
GridinsoftTrojan.Win32.Agent.oa
ArcabitTrojan.Agent.FAOU
AhnLab-V3Malware/Win32.RL_Generic.R358128
ZoneAlarmTrojan-Banker.Win32.RTM.fyg
GDataTrojan.Agent.FAOU
CynetMalicious (score: 100)
VBA32BScope.Backdoor.Vawtrak
ALYacTrojan.Agent.FAOU
MalwarebytesBackdoor.Qbot
TrendMicro-HouseCallTROJ_GEN.R002H0CLG20
RisingTrojan.MalCert!1.D055 (CLASSIC)
YandexTrojan.Qbot!+1DPKrWP8K0
FortinetW32/Kryptik.HDNN!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.61a

How to remove Trojan-Banker.Win32.RTM.fyg?

Trojan-Banker.Win32.RTM.fyg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment