Trojan

What is “Trojan-Banker.Win32.RTM.gvz”?

Malware Removal

The Trojan-Banker.Win32.RTM.gvz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.gvz virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.gvz?


File Info:

crc32: D10005B6
md5: c3d18c57ed1d765a28bf2e4a56fd9aff
name: C3D18C57ED1D765A28BF2E4A56FD9AFF.mlw
sha1: f5cb0a6dbcdfb150657bf0a8b8101e77128eefaf
sha256: 07d77c12004b8aeff6c0356874543cc715f6d74fea8fe9b672f34894d8ab71bd
sha512: 7726bcde7d6126bbd2cfb82577a81e020a55fa791387377d1fbfa8111ae09b491c0ba782e44107e93107fbee0181dd0a483caf94832a1a31bb6e675dc33d61de
ssdeep: 6144:Rt+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHd:rkvIfnMs596S9
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.gvz also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45134878
FireEyeGeneric.mg.c3d18c57ed1d765a
McAfeeGenericRXNC-RC!C3D18C57ED1D
CylanceUnsafe
AegisLabHacktool.Win32.Krap.lKMc
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.45134878
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZedlaF.34700.AE4@a85BGphi
CyrenW32/Kryptik.CUW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIKD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Bankerx-9817496-0
KasperskyTrojan-Banker.Win32.RTM.gvz
AlibabaTrojanBanker:Win32/Qakbot.04dcd9b0
TencentWin32.Trojan-banker.Rtm.Szkz
Ad-AwareTrojan.GenericKD.45134878
EmsisoftTrojan.GenericKD.45134878 (B)
F-SecureTrojan.TR/Crypt.Agent.pgsbi
DrWebBackDoor.Qbot.568
TrendMicroTROJ_GEN.R002C0RLO20
McAfee-GW-EditionBehavesLike.Win32.Trojan.vz
SophosMal/Generic-R + Mal/EncPk-APV
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Banker.RTM.ue
AviraTR/Crypt.Agent.pgsbi
MAXmalware (ai score=87)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GP!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2B0B41E
AhnLab-V3Trojan/Win32.Generic.C4275387
ZoneAlarmTrojan-Banker.Win32.RTM.gvz
GDataTrojan.GenericKD.45134878
CynetMalicious (score: 100)
VBA32BScope.Backdoor.Qbot
ALYacTrojan.GenericKD.45134878
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0RLO20
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
Qihoo-360Win32/Trojan.653

How to remove Trojan-Banker.Win32.RTM.gvz?

Trojan-Banker.Win32.RTM.gvz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment