Trojan

Trojan-Banker.Win32.RTM.hin (file analysis)

Malware Removal

The Trojan-Banker.Win32.RTM.hin is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hin virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hin?


File Info:

crc32: 61493C93
md5: 355eb152ec2a1db5a761f6001cafc3e2
name: 355EB152EC2A1DB5A761F6001CAFC3E2.mlw
sha1: b1ec1804175d27364818df60eb65cb72a79c9ce6
sha256: 5faa3f1dd99ebb429ff855c9e41e2e90ce0b2817599e6501d2900706d0ec3376
sha512: c8a1e47a3a728c285e2e06ccef85cde85b1e6babb2e12fa74580b3bb92b4df5a4d34ea5a046a01d6372f5bfc45db804218b4776fe3e83162bb510963a7b655a3
ssdeep: 6144:Ww+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdiqyP:dkvIfnMs596S9i7
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.hin also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.72231
FireEyeGeneric.mg.355eb152ec2a1db5
Qihoo-360Win32/Trojan.ad0
McAfeeGenericRXND-HL!355EB152EC2A
CylanceUnsafe
VIPRELooksLike.Win32.Zbot.b (v)
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKDZ.72231
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/Trojan.XRNX-3859
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.hin
AlibabaTrojanBanker:Win32/Qakbot.ef8a7bf7
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareTrojan.GenericKDZ.72231
SophosMal/Generic-R + Mal/EncPk-APV
F-SecureTrojan.TR/AD.Qbot.xdjef
DrWebBackDoor.Qbot.568
TrendMicroTROJ_GEN.R002C0RLR20
McAfee-GW-EditionGenericRXND-HL!355EB152EC2A
EmsisoftTrojan.GenericKDZ.72231 (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.RTM.us
AviraTR/AD.Qbot.xdjef
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D11A27
ZoneAlarmTrojan-Banker.Win32.RTM.hin
GDataTrojan.GenericKDZ.72231
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4280517
BitDefenderThetaGen:NN.ZedlaF.34700.CQ4@ay!jGhji
ALYacTrojan.GenericKDZ.72231
VBA32BScope.Trojan.Gatak
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HILJ
TrendMicro-HouseCallTROJ_GEN.R002C0RLR20
TencentWin32.Trojan-banker.Rtm.Liqw
eGambitUnsafe.AI_Score_92%
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.RTM.hin?

Trojan-Banker.Win32.RTM.hin removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment