Trojan

Trojan-Banker.Win32.RTM.ife removal tips

Malware Removal

The Trojan-Banker.Win32.RTM.ife is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.ife virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.ife?


File Info:

crc32: 0733C104
md5: 1b95bf8376950d08377ddbf00699707f
name: 1B95BF8376950D08377DDBF00699707F.mlw
sha1: 66d3ded612fd95e225ab92f7aeb61364a496b74f
sha256: 8781bae26ff42c02a134d98d7eeb73b983d2d8af5437e8949eca94c05975d420
sha512: 1314a916834993c1d4ebb740241f0371fa2d8b16f2cc967b2e37ad2aff5e9945c068af09c864fd7b1d11627db59761c07ea8d54f396ae0d2abd083aba5fc4df6
ssdeep: 6144:BGlqosvPLYZiWYG+0KTwmFI4Iu6WgEWasmlbUhDROt6:Yqo3ZLYGzKT95wWQFT9Ot
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009
InternalName: FGResDetector
FileVersion: 1, 0, 0, 1
ProductName: FGResDetector Module
ProductVersion: 1, 0, 0, 1
FileDescription: FGResDetector Module
OriginalFilename: FGResDetector.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.ife also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35981301
FireEyeGeneric.mg.1b95bf8376950d08
Qihoo-360Generic/Trojan.Generic.ec0
McAfeeW32/PinkSbot-HF!1B95BF837695
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2807987
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35981301
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZedlaF.34760.rE8@ai13S0oj
CyrenW32/Trojan.DSLT-4826
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.ife
AlibabaTrojanBanker:Win32/Qakbot.f378e273
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareTrojan.GenericKD.35981301
EmsisoftTrojan.GenericKD.35981301 (B)
F-SecureTrojan.TR/AD.Qbot.rdqpr
DrWebTrojan.Inject4.6433
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R011C0DA621
McAfee-GW-EditionW32/PinkSbot-HF!1B95BF837695
SophosMal/Generic-R + Mal/EncPk-APV
IkarusTrojan.Agent
JiangminTrojan.Banker.RTM.wm
AviraTR/AD.Qbot.rdqpr
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D22507F5
ZoneAlarmTrojan-Banker.Win32.RTM.ife
GDataTrojan.GenericKD.35981301
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R361969
VBA32Trojan.Fuerboos
ALYacTrojan.GenericKD.35981301
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HINE
TrendMicro-HouseCallTROJ_GEN.R011C0DA621
TencentWin32.Trojan-banker.Rtm.Eant
YandexTrojan.PWS.RTM!S7EmHfzwN0I
eGambitUnsafe.AI_Score_85%
FortinetW32/RTM.HINE!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.RTM.ife?

Trojan-Banker.Win32.RTM.ife removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment