Trojan

About “Trojan-Banker.Win32.RTM.hek” infection

Malware Removal

The Trojan-Banker.Win32.RTM.hek is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hek virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hek?


File Info:

crc32: 25C4F8E6
md5: 6e7557eaa92df64ae8b4f918676f8991
name: 6E7557EAA92DF64AE8B4F918676F8991.mlw
sha1: 8f28b5ef57af3a273b87eb0fda6819fccce6b34f
sha256: 128f6185061b6700c449c0f491073f0084e05812ca007ad16947a0e9d2e4f8f9
sha512: ff851b8da281c99ca9f84d7e06a1c27b61b86cca841899362270810853823396034bf248a67aa92df7db328145adfd662c59359367d41f44521c2d3f09afab33
ssdeep: 6144:H2+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdbNRRR:WkvIfnMs596S9b
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.hek also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.6e7557eaa92df64a
Qihoo-360Win32/Trojan.653
McAfeeGenericRXND-FA!6E7557EAA92D
CylanceUnsafe
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.35859088
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Trojan.LOJO-2145
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.RTM.hek
AlibabaTrojanBanker:Win32/Qakbot.5f4bd1d9
MicroWorld-eScanTrojan.GenericKD.35859088
TencentWin32.Trojan-banker.Rtm.Wrqr
Ad-AwareTrojan.GenericKD.35859088
SophosMal/Generic-R + Mal/EncPk-APV
F-SecureTrojan.TR/Crypt.Agent.dfgdj
TrendMicroTROJ_GEN.R002C0RLQ20
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
EmsisoftTrojan.GenericKD.35859088 (B)
JiangminTrojan.Banker.RTM.up
AviraTR/Crypt.Agent.dfgdj
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2232A90
AegisLabHacktool.Win32.Krap.lKMc
ZoneAlarmTrojan-Banker.Win32.RTM.hek
GDataTrojan.GenericKD.35859088
AhnLab-V3Malware/Win32.RL_Generic.R360772
BitDefenderThetaGen:NN.ZedlaF.34700.GM4@aaFms3vi
ALYacTrojan.GenericKD.35859088
VBA32Trojan.Inject
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIKT
TrendMicro-HouseCallTROJ_GEN.R002C0RLQ20
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
YandexTrojan.Kryptik!MOgeIpfVyNU
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]

How to remove Trojan-Banker.Win32.RTM.hek?

Trojan-Banker.Win32.RTM.hek removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment