Trojan

Trojan-Banker.Win32.RTM.gsk malicious file

Malware Removal

The Trojan-Banker.Win32.RTM.gsk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.gsk virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.gsk?


File Info:

crc32: 0F3664B9
md5: f884bc5572abbb666a768d8d4b7566aa
name: F884BC5572ABBB666A768D8D4B7566AA.mlw
sha1: 2580289f692e529b10c4709163e0bc1eeebe14bf
sha256: 7e3024219b0093adf1dff2519b76772f8763886cc4f4c7573e79a6bdab77fc6c
sha512: 8aade7497de4c6d4934683832e82098df2720669dfd0c941127946a1b9242c0e136ea5451a17abdca4ab79f336bd7054c9a727c798564fc9f0ba7679256d1090
ssdeep: 6144:+culCVt4kzCe3Py4WaJnOBZIHGzgzYarwVdICoOrTvll:pulcXCeK4fM8mrc02NOr7ll
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.gsk also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45144808
FireEyeGeneric.mg.f884bc5572abbb66
Qihoo-360HEUR/QVM40.1.29AE.Malware.Gen
McAfeeGenericRXAA-AA!F884BC5572AB
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderTrojan.GenericKD.45144808
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderThetaGen:NN.ZedlaF.34700.AE4@aG0n3Mhi
APEXMalicious
KasperskyTrojan-Banker.Win32.RTM.gsk
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareTrojan.GenericKD.45144808
EmsisoftTrojan.GenericKD.45144808 (B)
McAfee-GW-EditionBehavesLike.Win32.Android.vz
SophosML/PE-A + Mal/EncPk-APV
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=86)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GP!MTB
ArcabitTrojan.Generic.D2B0DAE8
ZoneAlarmTrojan-Banker.Win32.RTM.gsk
GDataTrojan.GenericKD.45144808
CynetMalicious (score: 100)
VBA32BScope.Backdoor.Qbot
ALYacTrojan.GenericKD.45144808
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIKD
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.HDNN!tr

How to remove Trojan-Banker.Win32.RTM.gsk?

Trojan-Banker.Win32.RTM.gsk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment