Trojan

What is “Trojan-Banker.Win32.RTM.gab”?

Malware Removal

The Trojan-Banker.Win32.RTM.gab is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.gab virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.gab?


File Info:

crc32: 88B8DDE6
md5: cfa26f1c25f403d23d5aa92a857d9b27
name: CFA26F1C25F403D23D5AA92A857D9B27.mlw
sha1: 3457599d824ab5cca5457b7705b7c638f1ad6145
sha256: 151a5fc61c2af6256518d47d4e1d3b1477300392644e73582c8a290fdfcf54b6
sha512: 9bc6552cdea6c145971ae5efb21dae98eb60641dd9ba38527559810e35fc16dcc84b118309eed98510811d7b9d905c23db0fe3ab65ec8bb072afa227522cf43f
ssdeep: 3072:hVqM8wnRCuoEXuEoUcfGOzLty3eIoyDdJQ3oH04Rs0AIs0AIs0AIs0AIs0AIs0A:wK/zcfGOzRb+UG0
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: appcmd.exe
FileVersion: 7.5.7601.17514 (win7sp1_rtm.101119-1850)
CompanyName: Microsoft Corporation
ProductName: Internet Information Services
ProductVersion: 7.5.7601.17514
FileDescription: Application Server Command Line Admin Tool
OriginalFilename: appcmd.exe
Translation: 0x0000 0x04b0

Trojan-Banker.Win32.RTM.gab also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.cfa26f1c25f403d2
McAfeeW32/PinkSbot-HJ!CFA26F1C25F4
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.35742116
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.RTM.gab
MicroWorld-eScanTrojan.GenericKD.35742116
RisingTrojan.Kryptik!1.CFFC (CLASSIC)
Ad-AwareTrojan.GenericKD.35742116
SophosML/PE-A + Mal/EncPk-APV
McAfee-GW-EditionBehavesLike.Win32.Generic.vz
EmsisoftTrojan.GenericKD.35742116 (B)
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
ArcabitTrojan.Generic.D22161A4
ZoneAlarmTrojan-Banker.Win32.RTM.gab
GDataTrojan.GenericKD.35742116
BitDefenderThetaGen:NN.ZedlaF.34700.os8@a0G7zmbi
ESET-NOD32a variant of Win32/Kryptik.HIHH
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HDNN!tr
Paloaltogeneric.ml
Qihoo-360HEUR/QVM40.1.FC6C.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.gab?

Trojan-Banker.Win32.RTM.gab removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment