Trojan

Trojan-Banker.Win32.RTM.gpq removal

Malware Removal

The Trojan-Banker.Win32.RTM.gpq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.gpq virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.gpq?


File Info:

crc32: 17D5E2B8
md5: 89035f14c63ca977afa3d3c6c424fb7b
name: 89035F14C63CA977AFA3D3C6C424FB7B.mlw
sha1: c93f01061b8b4e922ea683b51de89b0288c20a5f
sha256: 06b802e78e31e07a67d85f050c460072dc94b4c96f02ce6d0d63ddfab875371c
sha512: 70de45eb5b8ed4d1e3340b9c663e820f0cedaca08443df5e7e0e80807cc40211cd8d0e03b0d6f3731defcd2ed74ebb8393c6ba0eef9273764dfb5fdc09e6454c
ssdeep: 6144:N/+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHd:9kvIfnMs596S9
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.gpq also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.72161
FireEyeGeneric.mg.89035f14c63ca977
ALYacTrojan.GenericKDZ.72161
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderTrojan.GenericKDZ.72161
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
CyrenW32/Kryptik.CUW.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Banker.Win32.RTM.gpq
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareTrojan.GenericKDZ.72161
EmsisoftTrojan.GenericKDZ.72161 (B)
McAfee-GW-EditionBehavesLike.Win32.Trojan.vz
SophosML/PE-A + Mal/EncPk-APV
JiangminTrojan.Banker.RTM.tz
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Win32.Kryptik.oa!s1
ArcabitTrojan.Generic.D119E1
ZoneAlarmTrojan-Banker.Win32.RTM.gpq
GDataTrojan.GenericKDZ.72161
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.R359732
McAfeeW32/PinkSbot-HF!89035F14C63C
MAXmalware (ai score=84)
VBA32BScope.Backdoor.Qbot
MalwarebytesTrojan.TrickBot
ESET-NOD32a variant of Win32/Kryptik.HIKD
TencentMalware.Win32.Gencirc.10ce2b66
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HDNN!tr
BitDefenderThetaGen:NN.ZedlaF.34700.nE4@ai6Lcqei
AVGWin32:Trojan-gen
Qihoo-360HEUR/QVM40.1.2405.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.gpq?

Trojan-Banker.Win32.RTM.gpq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment