Trojan

How to remove “Trojan-Banker.Win32.RTM.hpj”?

Malware Removal

The Trojan-Banker.Win32.RTM.hpj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hpj virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hpj?


File Info:

crc32: F38856F8
md5: 8bb0794e036a3b86a66e4608da7df4a1
name: 8BB0794E036A3B86A66E4608DA7DF4A1.mlw
sha1: dacc81b27938ea7ad8afb302852e968b528489ea
sha256: a0f8d46b5e0ea1258a49fbea5d92952e0dcc2cea0fe3336461afb81927ed3598
sha512: 3ebe2165630b5e6ee65f6f369ae1384a77a2d87039bffc8eb669d50b9cc1b6376e4b2d9d7a8657895fd090cbc3b4df926656cc19cf2a4985bce2372949a62690
ssdeep: 6144:3d+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdO2:NkvIfnMs596S9O2
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2010
InternalName: Acala Software
FileVersion: 2, 0, 0, 1
CompanyName: Acala Software
ProductName: Acala Encoder Proxy
ProductVersion: 2.0.0.1
FileDescription: Acala Encoder Proxy
OriginalFilename: EncoderProxy.exe
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.RTM.hpj also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45242598
FireEyeGeneric.mg.8bb0794e036a3b86
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderTrojan.GenericKD.45242598
K7GWSpyware ( 0040f0131 )
K7AntiVirusSpyware ( 0040f0131 )
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Banker.Win32.RTM.hpj
Ad-AwareTrojan.GenericKD.45242598
EmsisoftTrojan.GenericKD.45242598 (B)
McAfee-GW-EditionArtemis!Trojan
SophosML/PE-A + Mal/EncPk-APV
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Heur!.02006020
ArcabitTrojan.Generic.D2B258E6
ZoneAlarmTrojan-Banker.Win32.RTM.hpj
GDataWin32.Trojan.QBot.EDAW24
CynetMalicious (score: 100)
McAfeeGenericRXNE-FJ!8BB0794E036A
MAXmalware (ai score=86)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HILY
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Dridex.TWY!tr
BitDefenderThetaGen:NN.ZedlaF.34700.xE8@aGU@nVij
AVGWin32:Malware-gen
Qihoo-360HEUR/QVM40.1.45C2.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.hpj?

Trojan-Banker.Win32.RTM.hpj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment