Trojan

Trojan-Banker.Win32.RTM.ijp removal

Malware Removal

The Trojan-Banker.Win32.RTM.ijp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.ijp virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.ijp?


File Info:

crc32: CB51490E
md5: 630e8a5335580d6469d2ff8f01dbe4de
name: 630E8A5335580D6469D2FF8F01DBE4DE.mlw
sha1: 16406ae8935511bc7de53ae2c3d747a944a984af
sha256: 60cc2bbd0312d656a1f1fc8454b3959d21b42752413a52c949dbf4bfa84cd0c6
sha512: b93966f7eb03929121d00fe1c5cce03d1f3bcb79cd29895b6d42496e979200e3120d8ffb169349b1b5ebbee4aee19b39e86db9b26a61f03318eb02e1baab916a
ssdeep: 6144:KGlqosvPLYZiWYG+0KTwmFI4Iu6WgEWasmlbUhDRa86:fqo3ZLYGzKT95wWQFT9a8
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2009
InternalName: FGResDetector
FileVersion: 1, 0, 0, 1
ProductName: FGResDetector Module
ProductVersion: 1, 0, 0, 1
FileDescription: FGResDetector Module
OriginalFilename: FGResDetector.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.ijp also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.6433
MicroWorld-eScanTrojan.GenericKDZ.72343
FireEyeGeneric.mg.630e8a5335580d64
Qihoo-360Win32/Trojan.653
McAfeeW32/PinkSbot-HF!630E8A533558
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.72343
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZedlaF.34742.rE8@aeM3XJaj
CyrenW32/Trojan.CGON-9144
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.ijp
AlibabaTrojanBanker:Win32/Qakbot.de565f28
AegisLabTrojan.Multi.Generic.4!c
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareTrojan.GenericKDZ.72343
EmsisoftTrojan.GenericKDZ.72343 (B)
ComodoMalware@#23b8nta1wids7
TrendMicroTROJ_GEN.R002C0RA421
McAfee-GW-EditionW32/PinkSbot-HF!630E8A533558
SophosMal/Generic-R + Mal/EncPk-APV
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qakbot.GA!MTB
GridinsoftRansom.Win32.Wacatac.oa
ArcabitTrojan.Generic.D11A97
ZoneAlarmTrojan-Banker.Win32.RTM.ijp
GDataTrojan.GenericKDZ.72343
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R361969
ALYacTrojan.GenericKDZ.72343
MAXmalware (ai score=85)
VBA32Trojan.Fuerboos
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HINE
TrendMicro-HouseCallTROJ_GEN.R002C0RA421
TencentWin32.Trojan-banker.Rtm.Wkvu
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_85%
FortinetW32/Dridex.TWY!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.RTM.ijp?

Trojan-Banker.Win32.RTM.ijp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment