Trojan

What is “Trojan-Banker.Win32.RTM.hvm”?

Malware Removal

The Trojan-Banker.Win32.RTM.hvm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hvm virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.hvm?


File Info:

crc32: 0CA0F4B0
md5: 11a3f194d583968863b7b39f91d55356
name: 11A3F194D583968863B7B39F91D55356.mlw
sha1: 13c6aceb3542b066db10c1c188c354d70c6c02f5
sha256: 68be940fb983ad37983a54c9c86aec9010c524f15f0ba07d467763f263010b4f
sha512: 7bcf48af301c6888703f439a77dce988a6a881bfb9f47f9d7b6ea79dbb6fdc8021074864fc67337d852c379c3236347d1c9e5d81a625748466eb3567d58b43c9
ssdeep: 6144:tGlqosvPLYZiWYG+0KTwmFI4Iu6WgEWasmlbUhDRDIdVDe7PEHf:8qo3ZLYGzKT95wWQFT9DIac/
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Connect to a Network Projector
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Connect to a Network Projector
OriginalFilename: NetProj.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.hvm also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.6407
MicroWorld-eScanTrojan.GenericKDZ.72326
FireEyeGeneric.mg.11a3f194d5839688
ALYacTrojan.GenericKDZ.72326
CylanceUnsafe
K7AntiVirusTrojan ( 005757e21 )
BitDefenderTrojan.GenericKDZ.72326
K7GWTrojan ( 005757e21 )
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderThetaGen:NN.ZedlaF.34742.uw8@aKr9Rjfi
CyrenW32/Trojan.KERJ-2494
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.hvm
AlibabaTrojanBanker:Win32/Qakbot.7f3c5df9
TencentWin32.Trojan-banker.Rtm.Dxdb
Ad-AwareTrojan.GenericKDZ.72326
EmsisoftTrojan.GenericKDZ.72326 (B)
ComodoMalware@#1eqfb6h3g2td9
F-SecureTrojan.TR/AD.Qbot.fbecd
TrendMicroTROJ_GEN.R067C0DA421
McAfee-GW-EditionBehavesLike.Win32.Trojan.vt
SophosMal/Generic-S + Mal/EncPk-APV
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.RTM.vo
AviraTR/AD.Qbot.fbecd
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.MK!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D11A86
ZoneAlarmTrojan-Banker.Win32.RTM.hvm
GDataTrojan.GenericKDZ.72326
CynetMalicious (score: 100)
McAfeeW32/PinkSbot-HF!11A3F194D583
MAXmalware (ai score=80)
VBA32BScope.Trojan.Diple
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HILY
TrendMicro-HouseCallTROJ_GEN.R067C0DA421
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
FortinetW32/Kryptik.HIDC!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM40.1.4B42.Malware.Gen

How to remove Trojan-Banker.Win32.RTM.hvm?

Trojan-Banker.Win32.RTM.hvm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment