Trojan

Trojan-Banker.Win32.RTM.hub (file analysis)

Malware Removal

The Trojan-Banker.Win32.RTM.hub is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hub virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hub?


File Info:

crc32: 498B67D7
md5: ef37cc247f1c74e6fcff29a37748a753
name: EF37CC247F1C74E6FCFF29A37748A753.mlw
sha1: f7363b47c98721167d49b12f8d8a647b65e102ff
sha256: c675c71bfeceb2efdd4b261e8b5476d19756ef3845a71f858f112f9d30fc5979
sha512: 5f8671fe0b3e0abb9e4fd4d71f104dd4ad6e1b93bb95cacd36b2af748207e7a9d486c381076291ea1869ade3a648577907c3c87e8e53bde1311d64206566f1f5
ssdeep: 6144:Evn+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdTCvy:MkvIfnMs596S9TCvy
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2016
InternalName: Java Control Panel
FileVersion: 11.121.2.13
Full Version: 11.121.2.13
CompanyName: Oracle Corporation
ProductName: Java(TM) Platform SE 8 U121
ProductVersion: 8.0.1210.13
FileDescription: Java Control Panel
OriginalFilename: javacpl.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.hub also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.ef37cc247f1c74e6
McAfeeGenericRXNE-LU!EF37CC247F1C
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderTrojan.GenericKD.45259620
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Trojan.UTKN-8051
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.RTM.hub
AlibabaTrojanBanker:Win32/Kryptik.bb9edace
AegisLabHacktool.Win32.Krap.lKMc
MicroWorld-eScanTrojan.GenericKD.45259620
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareTrojan.GenericKD.45259620
SophosMal/Generic-R + Mal/EncPk-APV
F-SecureTrojan.TR/AD.Qbot.tlpuu
DrWebTrojan.Inject4.6403
TrendMicroTROJ_GEN.R002C0RLV20
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.45259620 (B)
JiangminTrojan.Banker.RTM.vh
AviraTR/AD.Qbot.tlpuu
MAXmalware (ai score=86)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftProgram:Win32/Vigram.A
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D2B29B64
ZoneAlarmTrojan-Banker.Win32.RTM.hub
GDataTrojan.GenericKD.45259620
BitDefenderThetaGen:NN.ZedlaF.34700.ww8@aKfclJai
ALYacTrojan.GenericKD.45259620
VBA32BScope.Trojan.Diple
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HILY
TrendMicro-HouseCallTROJ_GEN.R002C0RLV20
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_95%
FortinetW32/Kryptik.HIDC!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.dd1

How to remove Trojan-Banker.Win32.RTM.hub?

Trojan-Banker.Win32.RTM.hub removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment