Trojan

Trojan-Banker.Win32.RTM.ixc information

Malware Removal

The Trojan-Banker.Win32.RTM.ixc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.ixc virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.RTM.ixc?


File Info:

crc32: 999E54E8
md5: f1b9778d0001e1ff9c0aa481a0827206
name: F1B9778D0001E1FF9C0AA481A0827206.mlw
sha1: 9762c5fab4235aca24d18bbc90f162649cb8c0ec
sha256: 16788e150fb95048543e59b5bcf8498b255b9d621a4b7c7db2ea6dbe75460561
sha512: 8a3226f36e4983f8a0c2523696cda64108e228aaeda19c515720d373d8bfcb5643e66eec4116e411f0978e2643146c8c94d4364073c645b22c0eacfeef6b3ffd
ssdeep: 6144:8psDm9m41qfMOSB5zMsP1DDK6DKFzz0Dnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn:FDp4dpMsNiAszz07
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.0
InternalName: ABCHelper.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: ABCHelper
ProductVersion: 1.0.0.0
FileDescription: ABCHelper
OriginalFilename: ABCHelper.exe
Translation: 0x0000 0x04b0

Trojan-Banker.Win32.RTM.ixc also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.6511
MicroWorld-eScanTrojan.GenericKD.36035522
FireEyeGeneric.mg.f1b9778d0001e1ff
McAfeeGenericRXNF-ZV!F1B9778D0001
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36035522
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.34760.DP8@aehZuph
CyrenW32/Qbot.BY.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H0CA821
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.RTM.ixc
AlibabaTrojanBanker:Win32/BankerX.9603a400
AegisLabHacktool.Win32.Krap.lKMc
Ad-AwareTrojan.GenericKD.36035522
EmsisoftTrojan.GenericKD.36035522 (B)
McAfee-GW-EditionGenericRXNF-ZV!F1B9778D0001
SentinelOneStatic AI – Suspicious PE
SophosML/PE-A + Mal/EncPk-APV
JiangminTrojan.Banker.RTM.wi
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D225DBC2
ZoneAlarmTrojan-Banker.Win32.RTM.ixc
GDataWin32.Trojan.QBot.TAEY4H
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R362441
MAXmalware (ai score=82)
MalwarebytesTrojan.Qbot
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32Win32/Qbot.CV
RisingTrojan.Kryptik!8.8 (TFE:2:ItOo6ejRx2)
YandexTrojan.Qbot!a+bgaBsnMqk
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]

How to remove Trojan-Banker.Win32.RTM.ixc?

Trojan-Banker.Win32.RTM.ixc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment