Trojan

Trojan-Banker.Win32.RTM.hjj removal

Malware Removal

The Trojan-Banker.Win32.RTM.hjj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hjj virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.hjj?


File Info:

crc32: 3D90C204
md5: 1e533006287872075d20241a8d152d7e
name: 1E533006287872075D20241A8D152D7E.mlw
sha1: 030f0c445edaa85b785eafbcec44b5b604f53ca4
sha256: 4ed9daa2491c4bdd0788e5d8b06d363a95bc0b802cf5fb7f30eaad1b6f589d82
sha512: 1da644015d2a3d0c083b8ca49ecd7729318d53079c2da73fcd59c5359f257ba1d357687de7d5d077b790a98e3109e8d5f93d8ee562a832ead5851c2b4684c81c
ssdeep: 6144:6w+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdHmyP:5kvIfnMs596S9H3
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.hjj also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.72231
McAfeeGenericRXND-HL!1E5330062878
CylanceUnsafe
VIPRELooksLike.Win32.Zbot.b (v)
SangforMalware
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderTrojan.GenericKDZ.72231
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.RTM.hjj
AlibabaTrojanBanker:Win32/Qakbot.c3caec2d
Ad-AwareTrojan.GenericKDZ.72231
EmsisoftTrojan.GenericKDZ.72231 (B)
DrWebBackDoor.Qbot.568
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-R + Mal/EncPk-APV
JiangminTrojan.Banker.RTM.us
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ZoneAlarmTrojan-Banker.Win32.RTM.hjj
GDataTrojan.GenericKDZ.72231
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4280517
BitDefenderThetaGen:NN.ZedlaF.34700.CQ4@aOKZldoi
ALYacTrojan.GenericKDZ.72231
MAXmalware (ai score=89)
VBA32BScope.Trojan.Gatak
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HILJ
TrendMicro-HouseCallTROJ_GEN.R002H0CLR20
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
eGambitUnsafe.AI_Score_92%
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]

How to remove Trojan-Banker.Win32.RTM.hjj?

Trojan-Banker.Win32.RTM.hjj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment