Trojan

What is “Trojan-Banker.Win32.RTM.idn”?

Malware Removal

The Trojan-Banker.Win32.RTM.idn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.idn virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.idn?


File Info:

crc32: 76C07DA9
md5: c009c58af5b96b4ab3982b34f00db98e
name: C009C58AF5B96B4AB3982B34F00DB98E.mlw
sha1: 929cc5b69c5133d4e7a10a61f8fb4296f6693ec1
sha256: a713050a6041e54313518076f584908c4436aa568ecc473aafb902a15ac30cbe
sha512: 5b6fe6d8fd16fd05c787c78a6a77aeb0b1211b320380fdb271468ca5d09c08d238ccbf67a13bf9a9a2c502a1de15f55016a6a9c77b4cad88c8b47426ca11f236
ssdeep: 6144:WwsjfhIZ77mLRMtvGUpRGcZ8yhHVh8f45mlaz666:NAhIZ77mL+pMxyVL8fePz66
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009
InternalName: FGResDetector
FileVersion: 1, 0, 0, 1
ProductName: FGResDetector Module
ProductVersion: 1, 0, 0, 1
FileDescription: FGResDetector Module
OriginalFilename: FGResDetector.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.idn also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.c009c58af5b96b4a
McAfeeGenericRXAA-AA!C009C58AF5B9
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45308465
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZedlaF.34742.rE8@aS!CQ4ij
CyrenW32/Trojan.ZRJZ-1954
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Qbot.CV
APEXMalicious
AvastWin32:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.RTM.idn
AlibabaTrojanBanker:Win32/BankerX.b2f2123e
AegisLabTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.45308465
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareTrojan.GenericKD.45308465
SophosMal/Generic-R + Mal/EncPk-APV
DrWebTrojan.Inject4.6427
TrendMicroTROJ_GEN.R011C0DA621
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.45308465 (B)
IkarusTrojan.SuspectCRC
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qbot.PVD!MTB
GridinsoftRansom.Win32.Wacatac.oa
ArcabitTrojan.Generic.D2B35A31
AhnLab-V3Malware/Win32.Generic.C4290372
ZoneAlarmTrojan-Banker.Win32.RTM.idn
GDataTrojan.GenericKD.45308465
ALYacTrojan.GenericKD.45308465
VBA32BScope.Trojan.Fuerboos
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R011C0DA621
TencentWin32.Trojan-banker.Rtm.Stjt
SentinelOneStatic AI – Suspicious PE
FortinetW32/Cridex.GYR!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.RTM.idn?

Trojan-Banker.Win32.RTM.idn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment