Trojan

Trojan-Banker.Win32.RTM.iid (file analysis)

Malware Removal

The Trojan-Banker.Win32.RTM.iid is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.iid virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.iid?


File Info:

crc32: 0E2DE566
md5: 4c8f26a0b12ba47f4f4c2b607e00b012
name: 4C8F26A0B12BA47F4F4C2B607E00B012.mlw
sha1: 76115afe8a8b36551f0d401a67cb5f1cd422b12b
sha256: 7c46733890bc2039e5845e7f54d485df850a090792e45c3e5609978bac7de0fa
sha512: 840eaf572442345d6372de41c347666b0af12e44fa2879ae47e8ae962b5ccf1af261622d0a22ff5b3763200ba998784abb1b6ec1df4ca1887500f7e002319aad
ssdeep: 6144:fwsjfhIZ77mLRMtvGUpRGcZ8yhHVh8f45mlaz976:4AhIZ77mL+pMxyVL8fePz97
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009
InternalName: FGResDetector
FileVersion: 1, 0, 0, 1
ProductName: FGResDetector Module
ProductVersion: 1, 0, 0, 1
FileDescription: FGResDetector Module
OriginalFilename: FGResDetector.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.iid also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35982027
FireEyeGeneric.mg.4c8f26a0b12ba47f
McAfeeW32/PinkSbot-HF!4C8F26A0B12B
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderTrojan.GenericKD.35982027
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZedlaF.34742.rE8@aSwVRPhj
CyrenW32/Trojan.CVFZ-7156
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HINE
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.iid
AlibabaTrojanBanker:Win32/Qakbot.dab993d5
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan-banker.Rtm.Pfjz
Ad-AwareTrojan.GenericKD.35982027
SophosMal/Generic-R + Mal/EncPk-APV
DrWebTrojan.Inject4.6432
TrendMicroTROJ_GEN.R002C0RA421
McAfee-GW-EditionW32/PinkSbot-HF!4C8F26A0B12B
EmsisoftTrojan.GenericKD.35982027 (B)
SentinelOneStatic AI – Suspicious PE
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftRansom.Win32.Wacatac.oa
ArcabitTrojan.Generic.D2250ACB
AhnLab-V3Malware/Win32.RL_Generic.R361969
ZoneAlarmTrojan-Banker.Win32.RTM.iid
GDataTrojan.GenericKD.35982027
CynetMalicious (score: 100)
VBA32Trojan.Fuerboos
ALYacTrojan.GenericKD.35982027
MAXmalware (ai score=80)
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0RA421
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HDZK!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.20d

How to remove Trojan-Banker.Win32.RTM.iid?

Trojan-Banker.Win32.RTM.iid removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment