Trojan

Trojan-Banker.Win32.RTM.imj removal guide

Malware Removal

The Trojan-Banker.Win32.RTM.imj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.imj virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.imj?


File Info:

crc32: 83816F38
md5: 749a9f6c29fc87e3d5bdd168b8a2c535
name: 749A9F6C29FC87E3D5BDD168B8A2C535.mlw
sha1: 3d75b8318930223ec6a80279b99e42325d59c4c6
sha256: a009e00e4ad1f50bcc31b8466caa1a12f03809d6da9df4921cdbc5906cce26fc
sha512: 8cdb6a160f228bf4ed7c7cfda2acdc98f720c4963b252614557b5f55eeefaa5222059437c1a231cf0ac01b9783768f5e3df39efb808f924c4f4eb3610740980d
ssdeep: 6144:GUa+SGoAaVZSz58otQvkYRybhlyH053mXSLYp83RAhc3mbMFmv4RQx83ubpQXGB:NacoPitsHUtsH032P
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: dxdiag.exe
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Microsoft DirectX Diagnostic Tool
OriginalFilename: dxdiag.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.RTM.imj also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45342333
FireEyeGeneric.mg.749a9f6c29fc87e3
ALYacTrojan.GenericKD.45342333
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.45342333
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.34742.qM8@amQtFBji
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.imj
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
Ad-AwareTrojan.GenericKD.45342333
EmsisoftTrojan.GenericKD.45342333 (B)
McAfee-GW-EditionArtemis!Trojan
SophosML/PE-A + Mal/EncPk-APV
GDataTrojan.GenericKD.45342333
Antiy-AVLGrayWare/Win32.Kryptik.ehls
ArcabitTrojan.Generic.D2B3DE7D
ZoneAlarmTrojan-Banker.Win32.RTM.imj
MicrosoftTrojan:Win32/Qakbot.GA!MTB
CynetMalicious (score: 100)
McAfeeGenericRXNF-NS!749A9F6C29FC
MAXmalware (ai score=84)
VBA32BScope.Trojan.Gatak
ESET-NOD32a variant of Win32/Kryptik.HIOM
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]

How to remove Trojan-Banker.Win32.RTM.imj?

Trojan-Banker.Win32.RTM.imj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment