Trojan

Should I remove “Trojan-Banker.Win32.RTM.gyd”?

Malware Removal

The Trojan-Banker.Win32.RTM.gyd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.gyd virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.gyd?


File Info:

crc32: 7C4C00AE
md5: e33ac4bd09a4af6da3eeca6723d4c060
name: E33AC4BD09A4AF6DA3EECA6723D4C060.mlw
sha1: 810186e01a2971250cc070b6c86e3fa17b516e2d
sha256: 493d704e8fe690204c4a9e08f101fbdaf798e9f55d228e0675c4a082369a5c80
sha512: c3fdef4b502157911990a8fff8d73ad724ad0891d486a4637e1bf4776756b88d4c7dc9d6654f2b9f3c3f46e25c86661e8b0636cb7006da2ed2e90c4ba8f06646
ssdeep: 6144:kN+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdeFRRR:CkvIfnMs596S9e
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.gyd also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.812782
FireEyeGeneric.mg.e33ac4bd09a4af6d
ALYacGen:Variant.Razy.812782
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Razy.DC66EE
APEXMalicious
KasperskyTrojan-Banker.Win32.RTM.gyd
BitDefenderGen:Variant.Razy.812782
Ad-AwareGen:Variant.Razy.812782
SophosML/PE-A + Mal/EncPk-APV
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Razy.812782 (B)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
GridinsoftTrojan.Win32.Kryptik.oa!s1
MicrosoftTrojan:Win32/Qakbot.GP!MTB
ZoneAlarmTrojan-Banker.Win32.RTM.gyd
GDataGen:Variant.Razy.812782
CynetMalicious (score: 100)
McAfeeGenericRXND-FA!E33AC4BD09A4
MAXmalware (ai score=86)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EZAX
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
FortinetW32/Kryptik.DZZ!tr
BitDefenderThetaGen:NN.ZedlaF.34700.II4@a4R8xLwi
AvastWin32:BankerX-gen [Trj]

How to remove Trojan-Banker.Win32.RTM.gyd?

Trojan-Banker.Win32.RTM.gyd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment