Trojan

Trojan-Banker.Win32.RTM.gzd (file analysis)

Malware Removal

The Trojan-Banker.Win32.RTM.gzd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.gzd virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.gzd?


File Info:

crc32: CA628208
md5: c6617612ceab8dbb0afc9fa98fac3f59
name: C6617612CEAB8DBB0AFC9FA98FAC3F59.mlw
sha1: a3304b484526a8baf31f6d6fb7322a190ee83336
sha256: 2dd6de453e6166afc4e9356d7e7ae8786c76ce4d1598f6d968fd4eba523233ad
sha512: d852b2f9a418caf59ac64aae1e198982567202b4cc69f0e52b3650ac2619e98183db1aca3981a43d992c949fad7196d28317d4c58513e86d40c0fed20f5aa10a
ssdeep: 6144:Ns+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdH1RRR:2kvIfnMs596S9H
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.gzd also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.6361
MicroWorld-eScanTrojan.GenericKD.35855607
FireEyeGeneric.mg.c6617612ceab8dbb
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.35855607
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderThetaGen:NN.ZedlaF.34700.GM4@auJm2mvi
APEXMalicious
KasperskyTrojan-Banker.Win32.RTM.gzd
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareTrojan.GenericKD.35855607
SophosML/PE-A + Mal/EncPk-APV
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
EmsisoftTrojan.GenericKD.35855607 (B)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2231CF7
ZoneAlarmTrojan-Banker.Win32.RTM.gzd
GDataTrojan.GenericKD.35855607
CynetMalicious (score: 100)
McAfeeGenericRXND-FA!C6617612CEAB
MAXmalware (ai score=86)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIKT
FortinetW32/Kryptik.HDNN!tr

How to remove Trojan-Banker.Win32.RTM.gzd?

Trojan-Banker.Win32.RTM.gzd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment