Trojan

Trojan-Banker.Win32.RTM.hiv removal tips

Malware Removal

The Trojan-Banker.Win32.RTM.hiv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hiv virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hiv?


File Info:

crc32: 38A74AD0
md5: d37bfa9b6f2e8bee264e608efaa56f1f
name: D37BFA9B6F2E8BEE264E608EFAA56F1F.mlw
sha1: 6bc5298f79e8be2261aa41da907607230e4654d7
sha256: 5037bf383439411dfd50cd9c5af02e93be193b256c3e793e380650a05437e3e8
sha512: 37640249a422e38170cfa426e48fd53f9b0e4ce7690c5b2dbc789dd49b52586e9b32d9a8bf5399cfa0b9ecc503d10f59e9692ee5713968a18b9afb7843a32b41
ssdeep: 6144:oO+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHd2uyP:NkvIfnMs596S92f
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.hiv also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.816286
FireEyeGeneric.mg.d37bfa9b6f2e8bee
ALYacGen:Variant.Razy.816286
CylanceUnsafe
AegisLabHacktool.Win32.Krap.lKMc
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Razy.816286
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderThetaGen:NN.ZedlaF.34700.CQ4@aShDk@di
CyrenW32/Kryptik.CVS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HILN
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.hiv
AlibabaTrojanBanker:Win32/Qakbot.55f8c3ec
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareGen:Variant.Razy.816286
EmsisoftGen:Variant.Razy.816286 (B)
DrWebBackDoor.Qbot.568
TrendMicroTROJ_GEN.R002C0RLS20
McAfee-GW-EditionGenericRXND-MI!D37BFA9B6F2E
SophosMal/Generic-R + Mal/EncPk-APV
IkarusTrojan.Win32.Krypt
JiangminTrojan.Banker.RTM.uu
MAXmalware (ai score=83)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Razy.DC749E
AhnLab-V3Malware/Win32.Generic.C4280517
ZoneAlarmTrojan-Banker.Win32.RTM.hiv
GDataGen:Variant.Razy.816286
CynetMalicious (score: 100)
McAfeeGenericRXND-MI!D37BFA9B6F2E
VBA32BScope.Trojan.Gatak
MalwarebytesBackdoor.Qbot
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0RLS20
TencentWin32.Trojan-banker.Rtm.Wqcx
eGambitUnsafe.AI_Score_92%
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.9b9

How to remove Trojan-Banker.Win32.RTM.hiv?

Trojan-Banker.Win32.RTM.hiv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment