Trojan

Trojan-Banker.Win32.RTM.hce removal guide

Malware Removal

The Trojan-Banker.Win32.RTM.hce is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hce virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.hce?


File Info:

crc32: ADDC1D4D
md5: 168dca29eadf87977ba24a83d7d92e9c
name: 168DCA29EADF87977BA24A83D7D92E9C.mlw
sha1: 5034385fc33733129209f6af35c8365784873f6e
sha256: 9ad068fabdff103b97af4c34ea8cacef9bf47ddf6f8b62edbe939a5b5021f798
sha512: 52c92c7d7af8e240da8daf550703a6990864dd5a59a6f5cdfdaff2efd928acfabb0bb5ce0baea3e19dadcd691505d72331d512abc5f7f3ae5e0e3e9ca7d06937
ssdeep: 6144:k2+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHd79RRR:lkvIfnMs596S97
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.hce also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35859938
McAfeeGenericRXND-FA!168DCA29EADF
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
AlibabaTrojanBanker:Win32/Qakbot.013e5adb
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Trojan.TBMU-3674
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0RLQ20
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.RTM.hce
BitDefenderTrojan.GenericKD.35859938
TencentWin32.Trojan-banker.Rtm.Dygz
Ad-AwareTrojan.GenericKD.35859938
EmsisoftTrojan.GenericKD.35859938 (B)
TrendMicroTROJ_GEN.R002C0RLQ20
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
SophosMal/Generic-R + Mal/EncPk-APV
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.RTM.up
Antiy-AVLGrayWare/Win32.Kryptik.ehls
GridinsoftTrojan.Win32.Kryptik.oa
ZoneAlarmTrojan-Banker.Win32.RTM.hce
MicrosoftTrojan:Win32/Qakbot.GA!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R360772
BitDefenderThetaGen:NN.ZedlaF.34700.GM4@aGi78Sti
ALYacTrojan.GenericKD.35859938
MAXmalware (ai score=89)
VBA32Trojan.Inject
MalwarebytesTrojan.Crypt
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HIKT
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
YandexTrojan.Kryptik!MOgeIpfVyNU
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.df7

How to remove Trojan-Banker.Win32.RTM.hce?

Trojan-Banker.Win32.RTM.hce removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment