Trojan

Trojan-Banker.Win32.RTM.iev removal guide

Malware Removal

The Trojan-Banker.Win32.RTM.iev is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.iev virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.iev?


File Info:

crc32: 96DEB1E5
md5: 0fdb5e2c7b947ee59097616f445e34bb
name: 0FDB5E2C7B947EE59097616F445E34BB.mlw
sha1: 580e85b8b366093d35c8da62857ae062e643544a
sha256: a10a2b7759682328dc01e7ffdc4ed30cdb46202cdd3559cf005ead041a279a80
sha512: ba87ac92529e21b7ce19766bc5dcbfb1d4b5b0aea4f86c92ab494b16e537a0ec69615645ce0111a0229845930d7e4002f9cfbd0834733d87d4c8b88ed11785d7
ssdeep: 6144:3wsjfhIZ77mLRMtvGUpRGcZ8yhHVh8f45mlazE76:AAhIZ77mL+pMxyVL8fePzE7
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009
InternalName: FGResDetector
FileVersion: 1, 0, 0, 1
ProductName: FGResDetector Module
ProductVersion: 1, 0, 0, 1
FileDescription: FGResDetector Module
OriginalFilename: FGResDetector.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.iev also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.45309405
FireEyeGeneric.mg.0fdb5e2c7b947ee5
McAfeeW32/PinkSbot-HF!0FDB5E2C7B94
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45309405
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (D)
CyrenW32/Trojan.TJNR-7547
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HINE
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.iev
AlibabaTrojanBanker:Win32/Qakbot.14aa2db6
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareTrojan.GenericKD.45309405
SophosMal/Generic-R + Mal/EncPk-APV
DrWebTrojan.Inject4.6432
TrendMicroTROJ_GEN.R011C0DA621
McAfee-GW-EditionW32/PinkSbot-HF!0FDB5E2C7B94
EmsisoftTrojan.GenericKD.45309405 (B)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2B35DDD
AhnLab-V3Malware/Win32.RL_Generic.R361969
ZoneAlarmTrojan-Banker.Win32.RTM.iev
GDataTrojan.GenericKD.45309405
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZedlaF.34742.rE8@aylmi5lj
ALYacTrojan.GenericKD.45309405
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R011C0DA621
TencentWin32.Trojan-banker.Rtm.Kqd
IkarusTrojan.SuspectCRC
FortinetW32/Kryptik.HDZK!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.RTM.iev?

Trojan-Banker.Win32.RTM.iev removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment