Trojan

Trojan-Banker.Win32.RTM.hjo information

Malware Removal

The Trojan-Banker.Win32.RTM.hjo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hjo virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.hjo?


File Info:

crc32: 7CBC1C4A
md5: 560105eb755a1882238e9f2dc5b2c8d4
name: 560105EB755A1882238E9F2DC5B2C8D4.mlw
sha1: e333654227c489d115612dacfc7105a027754cb0
sha256: c2bddfb2a2ad4f9a54b4d05047b557ced3bb9689b4da615a70e95e3838422d79
sha512: 956d985529b061c552842f5bb59fd8e22cbd0133177807aad65b2f399c1c8f2b89eb1df04ab05e80dd1e1d4b617be32d27a11451e27512d1e276be0afa468a3b
ssdeep: 6144:Ew+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdv0yP:DkvIfnMs596S9vF
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.hjo also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45188473
FireEyeGeneric.mg.560105eb755a1882
McAfeeGenericRXND-HL!560105EB755A
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderTrojan.GenericKD.45188473
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
CyrenW32/Trojan.MOXH-1986
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.hjo
AlibabaTrojanBanker:Win32/Qakbot.d5d4e344
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareTrojan.GenericKD.45188473
SophosMal/Generic-R + Mal/EncPk-APV
DrWebBackDoor.Qbot.568
VIPRELooksLike.Win32.Zbot.b (v)
McAfee-GW-EditionGenericRXND-HL!560105EB755A
EmsisoftTrojan.GenericKD.45188473 (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.RTM.us
MAXmalware (ai score=84)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa!s1
ArcabitTrojan.Generic.D2B18579
ZoneAlarmTrojan-Banker.Win32.RTM.hjo
GDataTrojan.GenericKD.45188473
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4280517
BitDefenderThetaGen:NN.ZedlaF.34700.CQ4@a8nLygci
ALYacTrojan.GenericKD.45188473
VBA32BScope.Trojan.Gatak
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HILJ
TrendMicro-HouseCallTROJ_GEN.R002H0CLR20
TencentWin32.Trojan-banker.Rtm.Staf
eGambitUnsafe.AI_Score_92%
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.RTM.hjo?

Trojan-Banker.Win32.RTM.hjo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment