Trojan

About “Trojan-Banker.Win32.RTM.hpf” infection

Malware Removal

The Trojan-Banker.Win32.RTM.hpf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hpf virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hpf?


File Info:

crc32: E1CF394B
md5: 9af836da2fe2dcb6515b14ea0f66db36
name: 9AF836DA2FE2DCB6515B14EA0F66DB36.mlw
sha1: 1ea26a5c82bab818d4570ff4c29bfb0971374a31
sha256: df20cedb1fd905f307bf4f12f9aae8390ab67502d27b26e103660007758c4221
sha512: 7d289354e43c208bdd7548ed668ef6eccb95cc3afb8b41f3975b744665797be147164cd6cb6c53fcb611c6aba1402bb94d7a532687249fe3cccf835ce75773a5
ssdeep: 6144:5c+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHda2:WkvIfnMs596S9a2
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2010
InternalName: Acala Software
FileVersion: 2, 0, 0, 1
CompanyName: Acala Software
ProductName: Acala Encoder Proxy
ProductVersion: 2.0.0.1
FileDescription: Acala Encoder Proxy
OriginalFilename: EncoderProxy.exe
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.RTM.hpf also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45241618
FireEyeGeneric.mg.9af836da2fe2dcb6
McAfeeGenericRXNE-FJ!9AF836DA2FE2
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.45241618
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_60% (D)
APEXMalicious
KasperskyTrojan-Banker.Win32.RTM.hpf
Ad-AwareTrojan.GenericKD.45241618
EmsisoftTrojan.GenericKD.45241618 (B)
McAfee-GW-EditionArtemis!Trojan
SophosML/PE-A + Mal/EncPk-APV
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=89)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Heur!.02006020
ArcabitTrojan.Generic.D2B25512
ZoneAlarmTrojan-Banker.Win32.RTM.hpf
GDataWin32.Trojan.QBot.KMN9WB
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZedlaF.34700.xE8@a48XXQej
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HILY
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
FortinetW32/Dridex.TWY!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360HEUR/QVM40.1.45C2.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.hpf?

Trojan-Banker.Win32.RTM.hpf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment