Trojan

Trojan-Banker.Win32.RTM.hxy (file analysis)

Malware Removal

The Trojan-Banker.Win32.RTM.hxy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.hxy virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.hxy?


File Info:

crc32: 5259F651
md5: 210137c7149ad36dc174287392f36362
name: 210137C7149AD36DC174287392F36362.mlw
sha1: db8670cf702f802732891aa985bcf5912bf5f910
sha256: 9d8496581dded3c9fbe07489b6907624433ad6cd945ec36d3792b1816a6310b1
sha512: eef18dcc15ed45f59b5bd7338db8a3555a0b3e13bfd68f4c4fc187343bc9d26ed54cfe8bdf9adbdbe2a4a6dfd80d999067673b8da2fc266aeba93e96c1c270d0
ssdeep: 6144:MwsjfhIZ77mLRMtvGUpRGcZ8yhHVh8f45mlazA61:fAhIZ77mL+pMxyVL8fePzA61
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: extractr.exe
FileVersion: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.17514
FileDescription: Wimfltr v2 extractor
OriginalFilename: extractr.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.hxy also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.FBKP
FireEyeGeneric.mg.210137c7149ad36d
Qihoo-360HEUR/QVM40.1.56DF.Malware.Gen
McAfeeGenericRXNE-QJ!210137C7149A
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.Agent.FBKP
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.hxy
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareTrojan.Agent.FBKP
SophosML/PE-A + Mal/EncPk-APV
DrWebTrojan.Inject4.6417
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.Agent.FBKP (B)
SentinelOneStatic AI – Suspicious PE
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Win32.Kryptik.oa!s6
ArcabitTrojan.Agent.FBKP
ZoneAlarmTrojan-Banker.Win32.RTM.hxy
GDataWin32.Trojan.QBot.I8GRX0
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZedlaF.34700.qA8@au27Ndei
ALYacTrojan.Agent.FBKP
MAXmalware (ai score=84)
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIMP
eGambitUnsafe.AI_Score_90%
FortinetW32/Kryptik.HIDC!tr
AVGWin32:BankerX-gen [Trj]

How to remove Trojan-Banker.Win32.RTM.hxy?

Trojan-Banker.Win32.RTM.hxy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment