Trojan

Trojan-Banker.Win32.RTM.ifh (file analysis)

Malware Removal

The Trojan-Banker.Win32.RTM.ifh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.ifh virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.ifh?


File Info:

crc32: AC71AC57
md5: 2d594f6bfa529358bdb72a9b1686c504
name: 2D594F6BFA529358BDB72A9B1686C504.mlw
sha1: f0c057ff06093ba64950748b3718d806ae23775f
sha256: 25c2f7063619a65170b3f7c373c04ee0a081181356ed472133951faf70fda72f
sha512: 9fa0099341c7b522d2775a47b01ed5ac222c7115cdd10a7fbfdc2870c2002bb5f05ad35f39302fd5cea68af8c78f03501339fe7c677fe010bcce02bcee5e50cd
ssdeep: 6144:XwsjfhIZ77mLRMtvGUpRGcZ8yhHVh8f45mlazX/6:gAhIZ77mL+pMxyVL8fePzX/
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009
InternalName: FGResDetector
FileVersion: 1, 0, 0, 1
ProductName: FGResDetector Module
ProductVersion: 1, 0, 0, 1
FileDescription: FGResDetector Module
OriginalFilename: FGResDetector.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.ifh also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.2d594f6bfa529358
McAfeeW32/PinkSbot-HF!2D594F6BFA52
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanBanker:Win32/Qakbot.6c77ed53
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (D)
CyrenW32/Trojan.DCFN-7184
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.RTM.ifh
BitDefenderTrojan.GenericKD.45310174
Paloaltogeneric.ml
MicroWorld-eScanTrojan.GenericKD.45310174
TencentWin32.Trojan-banker.Rtm.Hssv
Ad-AwareTrojan.GenericKD.45310174
SophosMal/Generic-R + Mal/EncPk-APV
F-SecureTrojan.TR/AD.Qbot.jindg
DrWebTrojan.Inject4.6432
ZillyaTrojan.Kryptik.Win32.2806566
TrendMicroTROJ_GEN.R011C0DA621
McAfee-GW-EditionW32/PinkSbot-HF!2D594F6BFA52
EmsisoftTrojan.GenericKD.45310174 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.45310174
JiangminTrojan.Banker.RTM.wm
AviraTR/AD.Qbot.jindg
Antiy-AVLGrayWare/Win32.Kryptik.ehls
GridinsoftRansom.Win32.Wacatac.oa
ArcabitTrojan.Generic.D2B360DE
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmTrojan-Banker.Win32.RTM.ifh
MicrosoftTrojan:Win32/Qakbot.GA!MTB
AhnLab-V3Malware/Win32.RL_Generic.R361969
BitDefenderThetaGen:NN.ZedlaF.34760.rE8@a4HjJPkj
ALYacTrojan.GenericKD.45310174
MAXmalware (ai score=84)
VBA32Trojan.Fuerboos
MalwarebytesTrojan.Crypt
ESET-NOD32a variant of Win32/Kryptik.HINE
TrendMicro-HouseCallTROJ_GEN.R011C0DA621
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.PWS.RTM!S7EmHfzwN0I
IkarusTrojan.Agent
eGambitUnsafe.AI_Score_71%
FortinetW32/RTM.HINE!tr
AVGWin32:BankerX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Trojan-Banker.Win32.RTM.ifh?

Trojan-Banker.Win32.RTM.ifh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment