Trojan

Trojan-Banker.Win32.RTM.gzq (file analysis)

Malware Removal

The Trojan-Banker.Win32.RTM.gzq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.gzq virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.gzq?


File Info:

crc32: B2D9E4E1
md5: 68dc523ed76fd78b73f3025c106a8f3e
name: 68DC523ED76FD78B73F3025C106A8F3E.mlw
sha1: 5826b22cfe81480985556363ce5be177eac33fe6
sha256: 73e3af02522595f505d222e5fafcddbb28e57ffc8aadd698d72c99701ed3cf62
sha512: da779b81945e7de755762d108571267ee4cb1c487eca9b87fdd374481e5b9e9d0410ef5f3cf371b01a174de2a0d49fbbf7d855124de92c46dc73d5bdc2ad3698
ssdeep: 6144:GuulCVt4kzCe3Py4WaJnOBZIHGzgzYarwVdICoOrTvlP9RRR:HulcXCeK4fM8mrc02NOr7lP
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.gzq also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.35856869
FireEyeGeneric.mg.68dc523ed76fd78b
ALYacTrojan.GenericKD.35856869
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.35856869
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Fbfk-9817495-0
KasperskyTrojan-Banker.Win32.RTM.gzq
AlibabaTrojanBanker:Win32/GenKryptik.09f361d5
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareTrojan.GenericKD.35856869
SophosMal/Generic-R + Mal/EncPk-APV
DrWebTrojan.Inject4.6364
TrendMicroTROJ_GEN.R002C0RLQ20
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
EmsisoftTrojan.GenericKD.35856869 (B)
JiangminTrojan.Banker.RTM.uo
MAXmalware (ai score=81)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D22321E5
ZoneAlarmTrojan-Banker.Win32.RTM.gzq
GDataTrojan.GenericKD.35856869
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R360772
McAfeeGenericRXNC-ZU!68DC523ED76F
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EZBU
TrendMicro-HouseCallTROJ_GEN.R002C0RLQ20
TencentMalware.Win32.Gencirc.11b7f0d4
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.HDNN!tr
BitDefenderThetaGen:NN.ZedlaF.34700.GM4@a4umZuqi
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
Qihoo-360Win32/Trojan.8cf

How to remove Trojan-Banker.Win32.RTM.gzq?

Trojan-Banker.Win32.RTM.gzq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment