Trojan

Trojan-Banker.Win32.RTM.hff removal instruction

Malware Removal

The Trojan-Banker.Win32.RTM.hff is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hff virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hff?


File Info:

crc32: D2606327
md5: bbc211458367be16bc8b3ddc3181734a
name: BBC211458367BE16BC8B3DDC3181734A.mlw
sha1: 4ace75ca61852d0322845cc95df7b642dbcc72ed
sha256: c8caa68474fb9cf10e893e2ab71a8d88fb2fbe5230e2b4c419bb926b9f345095
sha512: 0bf2b162cf1e389d5c0222869e118e9b9b5da69166f9ed9c5148f484831ac62419c391c9bc885bde56c31eb022c157604c04d4e99bb513c01598466715387907
ssdeep: 6144:R2+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdmtRRR:EkvIfnMs596S9m
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.hff also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35859631
FireEyeGeneric.mg.bbc211458367be16
Qihoo-360Win32/Trojan.653
McAfeeGenericRXND-US!BBC211458367
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.35859631
K7GWSpyware ( 0040f0131 )
CyrenW32/Trojan.XARZ-2351
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.hff
AlibabaTrojanBanker:Win32/Kryptik.9445bf9b
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareTrojan.GenericKD.35859631
EmsisoftTrojan.GenericKD.35859631 (B)
TrendMicroTROJ_GEN.R002C0RLQ20
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
SophosMal/Generic-R + Mal/EncPk-APV
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.RTM.up
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2232CAF
ZoneAlarmTrojan-Banker.Win32.RTM.hff
GDataTrojan.GenericKD.35859631
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R360772
BitDefenderThetaGen:NN.ZedlaF.34700.GM4@aiJ!w4ti
ALYacTrojan.GenericKD.35859631
MAXmalware (ai score=86)
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIKT
TrendMicro-HouseCallTROJ_GEN.R002C0RLQ20
TencentWin32.Trojan-banker.Rtm.Pjdi
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.RTM.hff?

Trojan-Banker.Win32.RTM.hff removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment