Trojan

How to remove “Trojan-Banker.Win32.RTM.hua”?

Malware Removal

The Trojan-Banker.Win32.RTM.hua is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hua virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hua?


File Info:

crc32: 8D698B62
md5: 9f91ce6e8c2a926ad5e1a5a4f947f638
name: 9F91CE6E8C2A926AD5E1A5A4F947F638.mlw
sha1: c314d22b56499982595156a29dbb53adebf3cd69
sha256: 2bc4a052557ed75f6b90c0b9aee645d29339cd3cd77613ba4e1f16e9b91f9be5
sha512: ee5a0ba11f456eae706b4a44a2facaff3a4bfdb736b1f1d1d2498bbe82c44421a3fe7b36bddf27d6b4dd7b25b2950b6556f0f961a50000b2465573dd7ad69bb3
ssdeep: 6144:Lv1+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdTGvy:hkvIfnMs596S9TGvy
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2016
InternalName: Java Control Panel
FileVersion: 11.121.2.13
Full Version: 11.121.2.13
CompanyName: Oracle Corporation
ProductName: Java(TM) Platform SE 8 U121
ProductVersion: 8.0.1210.13
FileDescription: Java Control Panel
OriginalFilename: javacpl.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.hua also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35937914
FireEyeGeneric.mg.9f91ce6e8c2a926a
McAfeeGenericRXNE-LU!9F91CE6E8C2A
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderTrojan.GenericKD.35937914
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZedlaF.34700.ww8@aCN90Dfi
CyrenW32/Trojan.KRFM-0355
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.hua
AlibabaTrojanBanker:Win32/Kryptik.e575de4e
AegisLabHacktool.Win32.Krap.lKMc
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareTrojan.GenericKD.35937914
SophosMal/Generic-R + Mal/EncPk-APV
F-SecureTrojan.TR/Crypt.Agent.fecmd
DrWebTrojan.Inject4.6403
TrendMicroTROJ_GEN.R002C0RLV20
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.35937914 (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.RTM.vh
AviraTR/Crypt.Agent.fecmd
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftProgram:Win32/Ymacco.AA2B
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D2245E7A
ZoneAlarmTrojan-Banker.Win32.RTM.hua
GDataTrojan.GenericKD.35937914
CynetMalicious (score: 100)
VBA32BScope.Trojan.Diple
ALYacTrojan.GenericKD.35937914
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HILY
TrendMicro-HouseCallTROJ_GEN.R002C0RLV20
eGambitUnsafe.AI_Score_95%
FortinetW32/Kryptik.HIDC!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.fa1

How to remove Trojan-Banker.Win32.RTM.hua?

Trojan-Banker.Win32.RTM.hua removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment