Trojan

About “Trojan-Banker.Win32.RTM.ifa” infection

Malware Removal

The Trojan-Banker.Win32.RTM.ifa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.ifa virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.ifa?


File Info:

crc32: 280D5EE2
md5: 5fbb6fa63041f63562ae6dbbfd32d2c6
name: 5FBB6FA63041F63562AE6DBBFD32D2C6.mlw
sha1: 0123b158a7f71458a3f3493a32bc5e77ba0485ac
sha256: 05296759f2ba0787a0b40f2cc82857b97b02e5b4bbe3d38b5393cec7c919edca
sha512: 3318c090c881546e7efa49036a4742fb08ce21f92d2b9922e5ca8f5f0fb7b74da2a6f07fe59ed904ff6c7d47aea1dfd76a0ee64b427f1be3b51808ed6434171d
ssdeep: 6144:IGlqosvPLYZiWYG+0KTwmFI4Iu6WgEWasmlbUhDRR26:5qo3ZLYGzKT95wWQFT9R2
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009
InternalName: FGResDetector
FileVersion: 1, 0, 0, 1
ProductName: FGResDetector Module
ProductVersion: 1, 0, 0, 1
FileDescription: FGResDetector Module
OriginalFilename: FGResDetector.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.ifa also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.5fbb6fa63041f635
McAfeeW32/PinkSbot-HF!5FBB6FA63041
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderTrojan.GenericKD.45309477
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Trojan.EIGF-9149
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.RTM.ifa
AlibabaTrojanBanker:Win32/Qakbot.7da03320
AegisLabTrojan.Win32.RTM.7!c
MicroWorld-eScanTrojan.GenericKD.45309477
Ad-AwareTrojan.GenericKD.45309477
SophosMal/Generic-R + Mal/EncPk-APV
F-SecureTrojan.TR/Crypt.Agent.rciuq
DrWebTrojan.Inject4.6433
ZillyaTrojan.Kryptik.Win32.2807987
TrendMicroTROJ_GEN.R011C0DA621
McAfee-GW-EditionW32/PinkSbot-HF!5FBB6FA63041
EmsisoftTrojan.GenericKD.45309477 (B)
IkarusTrojan.Agent
JiangminTrojan.Banker.RTM.wm
AviraTR/Crypt.Agent.rciuq
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2B35E25
ZoneAlarmTrojan-Banker.Win32.RTM.ifa
GDataTrojan.GenericKD.45309477
AhnLab-V3Malware/Win32.RL_Generic.R361969
BitDefenderThetaGen:NN.ZedlaF.34760.rE8@auSNQgdj
ALYacTrojan.GenericKD.45309477
VBA32Trojan.Fuerboos
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HINE
TrendMicro-HouseCallTROJ_GEN.R011C0DA621
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.PWS.RTM!S7EmHfzwN0I
eGambitUnsafe.AI_Score_85%
FortinetW32/RTM.HINE!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.RTM.ifa?

Trojan-Banker.Win32.RTM.ifa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment