Trojan

How to remove “Trojan-Banker.Win32.RTM.hkg”?

Malware Removal

The Trojan-Banker.Win32.RTM.hkg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hkg virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hkg?


File Info:

crc32: 84796796
md5: 71bcb53127cba30da78e617cd41c87ff
name: 71BCB53127CBA30DA78E617CD41C87FF.mlw
sha1: 4e4df8776f64a009042fd2d0e4f82546ee8b30ee
sha256: 9bf1a385f999c9afd297d61a7f739d930fdbf3db199ff342e90a4d1a4e8a67f5
sha512: 62a6f4478a35c265cab1c9d0abc00eb8947a027714a834fcad2d32098bc33c1878ee4927ee267cf41310f33efab1e59fd3deb8831c43c7543dfb2d8fb1599da1
ssdeep: 6144:Rc+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdXtyP:qkvIfnMs596S9XC
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.hkg also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.816286
FireEyeGeneric.mg.71bcb53127cba30d
ALYacGen:Variant.Razy.816286
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderGen:Variant.Razy.816286
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW32/Trojan.AUBY-2254
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.hkg
AlibabaTrojanBanker:Win32/Qakbot.be2409a9
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareGen:Variant.Razy.816286
EmsisoftGen:Variant.Razy.816286 (B)
DrWebBackDoor.Qbot.568
McAfee-GW-EditionArtemis!Trojan
SophosML/PE-A + Mal/EncPk-APV
MAXmalware (ai score=87)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Razy.DC749E
ZoneAlarmTrojan-Banker.Win32.RTM.hkg
GDataGen:Variant.Razy.816286
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4280517
McAfeeGenericRXND-MK!71BCB53127CB
VBA32BScope.Trojan.Gatak
MalwarebytesBackdoor.Qbot
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HILN
TrendMicro-HouseCallTROJ_GEN.R002H09LR20
TencentWin32.Trojan-banker.Rtm.Ahey
FortinetW32/Kryptik.HDNN!tr
BitDefenderThetaGen:NN.ZedlaF.34700.CQ4@aSCIRBli
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM39.1.351F.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.hkg?

Trojan-Banker.Win32.RTM.hkg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment