Trojan

Trojan-Banker.Win32.RTM.gus removal guide

Malware Removal

The Trojan-Banker.Win32.RTM.gus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.gus virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.gus?


File Info:

crc32: 5AD231A7
md5: 8fa44278b40fcea7269a15c3f5d16473
name: 8FA44278B40FCEA7269A15C3F5D16473.mlw
sha1: 78ba8b71542b79ebd0a8461f273ae4ed9f72ad04
sha256: 836cd0092c0758481cf4a47c165cf23a5eb1613917cb82a340f4ac1ade5fafa9
sha512: 6dd94e40ee91c510a0cb2285fc6f1797063b61f4d53937d8dbd982b4c59fbd49c366df67d2c5927482f736e1276f2a9064658f8f95bf79d788d22ee3372fe80c
ssdeep: 6144:nt+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHd:tkvIfnMs596S9
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.gus also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebBackDoor.Qbot.568
MicroWorld-eScanTrojan.GenericKD.35831855
FireEyeGeneric.mg.8fa44278b40fcea7
ALYacTrojan.GenericKD.35831855
CylanceUnsafe
AegisLabHacktool.Win32.Krap.lKMc
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.35831855
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZedlaF.34700.AE4@aWsJsbji
CyrenW32/Qbot.BP.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Packed.Bankerx-9817496-0
KasperskyTrojan-Banker.Win32.RTM.gus
AlibabaTrojanBanker:Win32/Qakbot.bb53fc3a
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareTrojan.GenericKD.35831855
EmsisoftTrojan.GenericKD.35831855 (B)
F-SecureTrojan.TR/Crypt.Agent.fecjx
TrendMicroTROJ_GEN.R002C0RLO20
McAfee-GW-EditionBehavesLike.Win32.Trojan.vz
SophosMal/Generic-R + Mal/EncPk-APV
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.RTM.ue
AviraTR/Crypt.Agent.fecjx
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GP!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D222C02F
ZoneAlarmTrojan-Banker.Win32.RTM.gus
GDataTrojan.GenericKD.35831855
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C4275387
McAfeeGenericRXNC-FR!8FA44278B40F
MAXmalware (ai score=84)
VBA32BScope.Backdoor.Qbot
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HIKD
TrendMicro-HouseCallTROJ_GEN.R002C0RLO20
TencentWin32.Trojan-banker.Rtm.Efbg
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.653

How to remove Trojan-Banker.Win32.RTM.gus?

Trojan-Banker.Win32.RTM.gus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment