Trojan

Trojan-Banker.Win32.RTM.iez removal instruction

Malware Removal

The Trojan-Banker.Win32.RTM.iez is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.iez virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.iez?


File Info:

crc32: 0596260D
md5: 828398aeb50aca37ca915058fcd6b7ba
name: 828398AEB50ACA37CA915058FCD6B7BA.mlw
sha1: 30d538bc6610917dbf0125912582f335ca5a229f
sha256: 04fd780b28ab750c2d00aa8818de6d10a5fb2ce968c019934252061203027b58
sha512: 50405e6b2c8ebb5e60a3faeea6b7a1ef78c78c6b2a13ca3970e7b52295bc69214cb92160fac2a773bd31758fac4b95f79f2056e4186ee53568e0360d9a3b06b3
ssdeep: 6144:zwsjfhIZ77mLRMtvGUpRGcZ8yhHVh8f45mlaqlP6:cAhIZ77mL+pMxyVL8fePqlP
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009
InternalName: FGResDetector
FileVersion: 1, 0, 0, 1
ProductName: FGResDetector Module
ProductVersion: 1, 0, 0, 1
FileDescription: FGResDetector Module
OriginalFilename: FGResDetector.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.iez also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.6432
MicroWorld-eScanTrojan.GenericKD.35981407
McAfeeW32/PinkSbot-HF!828398AEB50A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35981407
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZedlaF.34760.rE8@a8lA!Eij
CyrenW32/Trojan.XLLY-5470
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.RTM.iez
AlibabaTrojanBanker:Win32/Qakbot.1865bb80
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan-banker.Rtm.Dzjn
Ad-AwareTrojan.GenericKD.35981407
SophosMal/Generic-R + Mal/EncPk-APV
ZillyaTrojan.Kryptik.Win32.2806566
TrendMicroTROJ_GEN.R011C0DA621
McAfee-GW-EditionW32/PinkSbot-HF!828398AEB50A
EmsisoftTrojan.GenericKD.35981407 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Banker.RTM.wm
Antiy-AVLGrayWare/Win32.Kryptik.ehls
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D225085F
ZoneAlarmTrojan-Banker.Win32.RTM.iez
GDataTrojan.GenericKD.35981407
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R361969
VBA32Trojan.Fuerboos
ALYacTrojan.GenericKD.35981407
MalwarebytesTrojan.Crypt
ESET-NOD32a variant of Win32/Kryptik.HINE
TrendMicro-HouseCallTROJ_GEN.R011C0DA621
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.PWS.RTM!S7EmHfzwN0I
MAXmalware (ai score=82)
FortinetW32/RTM.HINE!tr
PandaTrj/Genetic.gen

How to remove Trojan-Banker.Win32.RTM.iez?

Trojan-Banker.Win32.RTM.iez removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment