Trojan

How to remove “Trojan-Banker.Win32.RTM.han”?

Malware Removal

The Trojan-Banker.Win32.RTM.han is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.han virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.han?


File Info:

crc32: 2392E120
md5: 21c5daac0bd7eb549ef56edd514821dd
name: 21C5DAAC0BD7EB549EF56EDD514821DD.mlw
sha1: bd5c7500c7f4c26a391040484438638184df737b
sha256: d2c9e42153e359c5c9043faeac46df3ef9ae16e534a38a774d3780cf0fcca69d
sha512: 5dbfc048ef856c53915888b95e5ce54d11f6b69f15dbaa7891de3ef030665de781878207ae21701da74ead3296daf1b02e725517ef83a6238e50e1bc7afb3e6b
ssdeep: 6144:ruulCVt4kzCe3Py4WaJnOBZIHGzgzYarwVdICoOrTvlyVRRR:yulcXCeK4fM8mrc02NOr7ly
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.han also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.6364
MicroWorld-eScanTrojan.GenericKD.45166019
FireEyeGeneric.mg.21c5daac0bd7eb54
McAfeeGenericRXND-FA!21C5DAAC0BD7
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.45166019
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderThetaGen:NN.ZedlaF.34700.GM4@aKvUGYBi
APEXMalicious
ClamAVWin.Malware.Fbfk-9817495-0
KasperskyTrojan-Banker.Win32.RTM.han
Ad-AwareTrojan.GenericKD.45166019
SophosML/PE-A + Mal/EncPk-APV
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
EmsisoftTrojan.GenericKD.45166019 (B)
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2B12DC3
ZoneAlarmTrojan-Banker.Win32.RTM.han
GDataTrojan.GenericKD.45166019
CynetMalicious (score: 100)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EZBU
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
FortinetW32/Kryptik.HDNN!tr

How to remove Trojan-Banker.Win32.RTM.han?

Trojan-Banker.Win32.RTM.han removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment