Trojan

Trojan-Banker.Win32.RTM.hfc (file analysis)

Malware Removal

The Trojan-Banker.Win32.RTM.hfc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hfc virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hfc?


File Info:

crc32: D0C8CAEA
md5: d294f9bf109d0c6e74364f092f46b611
name: D294F9BF109D0C6E74364F092F46B611.mlw
sha1: 50aa33c1d3057475a011a26edcfe815496922120
sha256: 0b77026866955f2e94e9916dae70bd6d5e0fe8e5d69c805f69c28556434d6c4b
sha512: 87c3bb729907999794e170748b329a745199917c5f046bac234f6b42bdf46033e2352e1a3b858e7ba3c0f08c8623a0f783fc95df2ae894923759755846962dd2
ssdeep: 6144:wUulCVt4kzCe3Py4WaJnOBZIHGzgzYarwVdICoOrTvlplRRR:TulcXCeK4fM8mrc02NOr7lp
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.hfc also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45166964
FireEyeGeneric.mg.d294f9bf109d0c6e
McAfeeGenericRXND-US!D294F9BF109D
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.45166964
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Trojan.KHFH-4000
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Fbfk-9817495-0
KasperskyTrojan-Banker.Win32.RTM.hfc
AlibabaTrojanBanker:Win32/Qakbot.5ed8ac12
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareTrojan.GenericKD.45166964
EmsisoftTrojan.GenericKD.45166964 (B)
F-SecureTrojan.TR/Kryptik.gqeel
DrWebTrojan.Inject4.6365
TrendMicroTROJ_GEN.R002C0RLQ20
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
SophosMal/Generic-R + Mal/EncPk-APV
IkarusTrojan.Win32.Krypt
JiangminTrojan.Banker.RTM.up
AviraTR/Kryptik.gqeel
MAXmalware (ai score=89)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2B13174
ZoneAlarmTrojan-Banker.Win32.RTM.hfc
GDataTrojan.GenericKD.45166964
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R360772
VBA32Trojan.Inject
ALYacTrojan.GenericKD.45166964
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HILZ
TrendMicro-HouseCallTROJ_GEN.R002C0RLQ20
TencentWin32.Trojan-banker.Rtm.Wqmm
YandexTrojan.Kryptik!MOgeIpfVyNU
FortinetW32/Kryptik.HDNN!tr
BitDefenderThetaGen:NN.ZedlaF.34700.GM4@ay9eNIri
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
Qihoo-360Generic/HEUR/QVM39.1.2FF7.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.hfc?

Trojan-Banker.Win32.RTM.hfc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment