Trojan

Trojan-Banker.Win32.RTM.fzg removal instruction

Malware Removal

The Trojan-Banker.Win32.RTM.fzg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.fzg virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup

How to determine Trojan-Banker.Win32.RTM.fzg?


File Info:

crc32: FDAB1CAA
md5: 151686476f5712114fa13e1fe1b6b37d
name: 151686476F5712114FA13E1FE1B6B37D.mlw
sha1: 4d474f26d853579d9724b7f10aa06ffa0bc2922a
sha256: d271138e8a816bfabb925e1ad35bc177a54469ff2a3d25ce09442d16ee688fb1
sha512: e19b7bd61955da96f73cc18468fae0b051ca2aac87b46b7d357576c634c20671a868c302bdea5d7698ff0582e0ca284f3f14283a6b973e8a67460362e0915bca
ssdeep: 6144:yju221F3vwlGw75yFFzmxoZagb8iVKQnPQ7bV2qt6:X4HVyFFzBZFS6
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: vbc.exe
FileVersion: 8.0.50727.5420
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Visual Studioxae 2005
ProductVersion: 8.0.50727.5420
FileDescription: Visual Basic Command Line Compiler
OriginalFilename: vbc.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.fzg also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35734410
FireEyeGeneric.mg.151686476f571211
ALYacTrojan.GenericKD.35734410
CylanceUnsafe
SangforMalware
K7AntiVirusBackdoor ( 00573a651 )
BitDefenderTrojan.GenericKD.35734410
K7GWBackdoor ( 00573a651 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.34700.n!8@aSJVe3li
CyrenW32/Kryptik.CSQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Qbot.CU
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Packed.Qbot-9810626-0
KasperskyTrojan-Banker.Win32.RTM.fzg
AegisLabHacktool.Win32.Krap.lKMc
RisingTrojan.Kryptik!1.CFFC (CLASSIC)
Ad-AwareTrojan.GenericKD.35734410
EmsisoftTrojan.GenericKD.35734410 (B)
F-SecureTrojan.TR/AD.Qbot.muyko
DrWebBackDoor.Qbot.550
TrendMicroTROJ_GEN.R002C0RLG20
McAfee-GW-EditionArtemis!Trojan
SophosML/PE-A + Mal/EncPk-APV
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Banker.RTM.th
AviraTR/AD.Qbot.muyko
MAXmalware (ai score=87)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.ZX!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D221438A
AhnLab-V3Malware/Win32.RL_Generic.R358128
ZoneAlarmTrojan-Banker.Win32.RTM.fzg
GDataTrojan.GenericKD.35734410
CynetMalicious (score: 100)
McAfeeW32/PinkSbot-HJ!151686476F57
MalwarebytesTrojan.Qbot
TrendMicro-HouseCallTROJ_GEN.R002C0RLG20
YandexTrojan.PWS.RTM!NaQJzYXWyI0
IkarusBackdoor.QBot
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.421

How to remove Trojan-Banker.Win32.RTM.fzg?

Trojan-Banker.Win32.RTM.fzg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment