Trojan

Trojan-Banker.Win32.RTM.hhf removal

Malware Removal

The Trojan-Banker.Win32.RTM.hhf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hhf virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hhf?


File Info:

crc32: F151FB40
md5: 66adf2e8e5561bf7cf3f3cb50d9256bf
name: 66ADF2E8E5561BF7CF3F3CB50D9256BF.mlw
sha1: 4660be594b83147804564f04543e3ccc26dd44b9
sha256: ca07735d51005cb63d1a5b6c213f6016e1d0fca26addbe8591f8acbf4147d777
sha512: c058776a73bc487e5c7f60b86c121ca2d1cdf19774639fe44232ce73cbf5cd91aa5b350dabcb8d6ba540f97db6f15843f6ec981ad2947bdf2d4a0b55b18f534f
ssdeep: 6144:iUulCVt4kzCe3Py4WaJnOBZIHGzgzYarwVdICoOrTvlkpRRR:VulcXCeK4fM8mrc02NOr7lk
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.hhf also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.6365
MicroWorld-eScanTrojan.GenericKD.35859547
FireEyeGeneric.mg.66adf2e8e5561bf7
ALYacTrojan.GenericKD.35859547
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.35859547
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderThetaGen:NN.ZedlaF.34700.GM4@aSE!6qri
CyrenW32/Trojan.DLPL-2651
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Malware.Fbfk-9817495-0
KasperskyTrojan-Banker.Win32.RTM.hhf
AlibabaTrojanBanker:Win32/GenKryptik.43b01d27
TencentWin32.Trojan-banker.Rtm.Wptt
Ad-AwareTrojan.GenericKD.35859547
SophosMal/Generic-R + Mal/EncPk-APV
TrendMicroTROJ_GEN.R002C0RLQ20
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
EmsisoftTrojan.GenericKD.35859547 (B)
IkarusTrojan.Win32.Krypt
JiangminTrojan.Banker.RTM.up
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2232C5B
ZoneAlarmTrojan-Banker.Win32.RTM.hhf
GDataTrojan.GenericKD.35859547
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R360772
McAfeeGenericRXND-US!66ADF2E8E556
VBA32Trojan.Inject
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HILZ
TrendMicro-HouseCallTROJ_GEN.R002C0RLQ20
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
YandexTrojan.Kryptik!MOgeIpfVyNU
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.653

How to remove Trojan-Banker.Win32.RTM.hhf?

Trojan-Banker.Win32.RTM.hhf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment