Trojan

What is “Trojan-Banker.Win32.RTM.gyb”?

Malware Removal

The Trojan-Banker.Win32.RTM.gyb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.gyb virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.gyb?


File Info:

crc32: 357B3988
md5: 8c917b1595942f731253cb6eaf520679
name: 8C917B1595942F731253CB6EAF520679.mlw
sha1: 6d91dc2864aea1d0e0f3720e9710b05d89503f42
sha256: ca02c1e7bc3e6448345d059bd5cfcc7bc04a2899def85a11b6e1d2c5826957b9
sha512: 33435005fc739bf0cbf390cd2a2a3c218f2683583cc06794be2a543d087ea8f634ee034e9fb45dfb40eab6321658b89adbed8bc73703132f53a8814cbf1d6bce
ssdeep: 6144:a3ulCVt4kzCe3Py4WaJnOBZIHGzgzYarwVdICoOrTvlE1RRR:CulcXCeK4fM8mrc02NOr7lE
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.gyb also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.812782
FireEyeGeneric.mg.8c917b1595942f73
ALYacGen:Variant.Razy.812782
SangforMalware
CrowdStrikewin/malicious_confidence_90% (D)
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderThetaGen:NN.ZedlaF.34700.II4@aqQaURqi
APEXMalicious
ClamAVWin.Malware.Fbfk-9817495-0
KasperskyTrojan-Banker.Win32.RTM.gyb
BitDefenderGen:Variant.Razy.812782
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareGen:Variant.Razy.812782
EmsisoftGen:Variant.Razy.812782 (B)
McAfee-GW-EditionArtemis!Trojan
SophosML/PE-A + Mal/EncPk-APV
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GP!MTB
GridinsoftTrojan.Win32.Kryptik.oa!s1
ArcabitTrojan.Razy.DC66EE
ZoneAlarmTrojan-Banker.Win32.RTM.gyb
GDataGen:Variant.Razy.812782
CynetMalicious (score: 100)
McAfeeGenericRXND-FA!8C917B159594
CylanceUnsafe
ESET-NOD32a variant of Win32/GenKryptik.EZAX
FortinetW32/Kryptik.DZZ!tr
PandaTrj/GdSda.A

How to remove Trojan-Banker.Win32.RTM.gyb?

Trojan-Banker.Win32.RTM.gyb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment