Trojan

Trojan-Banker.Win32.RTM.hjq removal instruction

Malware Removal

The Trojan-Banker.Win32.RTM.hjq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hjq virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.hjq?


File Info:

crc32: CA19356C
md5: 8aa13ada9939d53f21167717ada932b4
name: 8AA13ADA9939D53F21167717ADA932B4.mlw
sha1: 2451bfac4106f4aeaaf854a840e7c936c8b0519a
sha256: 00ac432a6e66e6d9b96d143b8f15de6d7f60c5b5d86c2c0f996750c298c70aef
sha512: 28162c3a45ba246d0d30ed6136b12f12b9c46453bf40974db9d2ac5054c8db80d653642a01742333bcffcd7d3ecccfdffd2dadb238efb18bbcc84787dcefbbba
ssdeep: 6144:Tc+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdd3yP:QkvIfnMs596S9dM
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.hjq also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.Qbot.568
FireEyeGeneric.mg.8aa13ada9939d53f
ALYacGen:Variant.Razy.816286
MalwarebytesBackdoor.Qbot
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Razy.816286
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderThetaGen:NN.ZedlaF.34700.CQ4@aCEG6pci
CyrenW32/Trojan.RBQJ-2271
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HILN
APEXMalicious
AvastWin32:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.RTM.hjq
AlibabaTrojanBanker:Win32/Qakbot.43e8826f
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
EmsisoftGen:Variant.Razy.816286 (B)
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-R + Mal/EncPk-APV
Antiy-AVLGrayWare/Win32.Kryptik.ehls
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Razy.DC749E
ZoneAlarmTrojan-Banker.Win32.RTM.hjq
GDataGen:Variant.Razy.816286
AhnLab-V3Malware/Win32.Generic.C4280517
VBA32BScope.Trojan.Gatak
PandaTrj/GdSda.A
TencentWin32.Trojan-banker.Rtm.Eddx
IkarusTrojan.SuspectCRC
eGambitUnsafe.AI_Score_88%
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM39.1.351F.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.hjq?

Trojan-Banker.Win32.RTM.hjq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment