Trojan

Trojan-Banker.Win32.RTM.ham (file analysis)

Malware Removal

The Trojan-Banker.Win32.RTM.ham is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.ham virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.ham?


File Info:

crc32: 69E6AFDF
md5: d5df1d5abed0deb4543e5c75d54356fc
name: D5DF1D5ABED0DEB4543E5C75D54356FC.mlw
sha1: a1cc0c6601597ea4448f61e841ac223a5b3d5a42
sha256: b510c71fee9aefa1ad4a11f7c32fa5eecc2f0d3d6adeaa5d3cba0ad62737ae76
sha512: a6a360aa2dfe30f5c05d393ad6e8c4019098ebb31a0d63c9cccae1e57d4a2f7dea9a352fcc3412bfe53e76c609890de734c49e48fc5cde5dd89d9b2cfc7ea508
ssdeep: 6144:rs+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdutRRR:AkvIfnMs596S9u
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.ham also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35858434
FireEyeGeneric.mg.d5df1d5abed0deb4
McAfeeGenericRXND-FA!D5DF1D5ABED0
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.35858434
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderThetaGen:NN.ZedlaF.34700.GM4@aSrREBDi
APEXMalicious
KasperskyTrojan-Banker.Win32.RTM.ham
Ad-AwareTrojan.GenericKD.35858434
EmsisoftTrojan.GenericKD.35858434 (B)
DrWebTrojan.Inject4.6361
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
SophosML/PE-A + Mal/EncPk-APV
GDataTrojan.GenericKD.35858434
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
ArcabitTrojan.Generic.D2232802
ZoneAlarmTrojan-Banker.Win32.RTM.ham
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIKT
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
FortinetW32/Kryptik.HDNN!tr

How to remove Trojan-Banker.Win32.RTM.ham?

Trojan-Banker.Win32.RTM.ham removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment