Trojan

Trojan-Banker.Win32.RTM.hpk removal guide

Malware Removal

The Trojan-Banker.Win32.RTM.hpk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hpk virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hpk?


File Info:

crc32: E88DD4FA
md5: a77abed6d7e020467d22acded8e953a0
name: A77ABED6D7E020467D22ACDED8E953A0.mlw
sha1: 54fceb1ec0550c02439573d372ef18faa1285e9c
sha256: f9f607434fb205cbf5c1b7c43f4573fc47624b767c40c9df685aff907a6daa7c
sha512: 517f1f96396eda482957bbe51ce59816db6651265e1a0180c20699a1e4f0930e7e6691226d99edf481ce24a2da2448c2f0fffbfffdbb60efd563107d0633b690
ssdeep: 6144:n/+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdi2:/kvIfnMs596S9i2
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2010
InternalName: Acala Software
FileVersion: 2, 0, 0, 1
CompanyName: Acala Software
ProductName: Acala Encoder Proxy
ProductVersion: 2.0.0.1
FileDescription: Acala Encoder Proxy
OriginalFilename: EncoderProxy.exe
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.RTM.hpk also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45242638
FireEyeGeneric.mg.a77abed6d7e02046
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.45242638
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZedlaF.34700.xE8@aq0@9jij
ESET-NOD32a variant of Win32/Kryptik.HILY
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Banker.Win32.RTM.hpk
Ad-AwareTrojan.GenericKD.45242638
SophosML/PE-A + Mal/EncPk-APV
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.45242638 (B)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Heur!.02006020
ArcabitTrojan.Generic.D2B2590E
ZoneAlarmTrojan-Banker.Win32.RTM.hpk
GDataWin32.Trojan.QBot.IJFQ9J
CynetMalicious (score: 100)
McAfeeGenericRXNE-FJ!A77ABED6D7E0
PandaTrj/GdSda.A
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
FortinetW32/Dridex.TWY!tr
AVGWin32:Malware-gen
Qihoo-360HEUR/QVM40.1.45C2.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.hpk?

Trojan-Banker.Win32.RTM.hpk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment