Trojan

What is “Trojan-Banker.Win32.RTM.jfx”?

Malware Removal

The Trojan-Banker.Win32.RTM.jfx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.RTM.jfx virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.RTM.jfx?


File Info:

crc32: 8367A408
md5: 63afca355abcf7d95cd450d66f05f633
name: 63AFCA355ABCF7D95CD450D66F05F633.mlw
sha1: c11ec556ee69ec608c43b08726d520e420830319
sha256: 0948d6f1da468b0ed049e41de8909d4bee0243e363e56249b437ce0a76c09ad4
sha512: 0e83e58b3fba05cbafb5294f6e1564422229df2e9becbce3ae67af67c52852722c84d2bd982f06c37b0429aacbc496194b484c59093c6e13b95b81f019395974
ssdeep: 3072:S1yTPwsRxtUR+7Jl/c8Mf5SqohUuJXtQOo2ZpJSG:HPwKnz4fe2mtQWZpUG
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.RTM.jfx also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Emotet.1091
MicroWorld-eScanTrojan.GenericKD.36095964
FireEyeGeneric.mg.63afca355abcf7d9
CAT-QuickHealTrojan.Multi
McAfeeDrixed-FJZ!63AFCA355ABC
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.36095964
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZedlaF.34760.uy5@aKprQVj
CyrenW32/Emotet.BAI.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_FRS.0NA103AD21
AvastWin32:CrypterX-gen [Trj]
ClamAVWin.Malware.Generickdz-9820666-0
KasperskyTrojan-Banker.Win32.RTM.jfx
AlibabaTrojanBanker:Win32/EmotetCrypt.f74e0222
ViRobotTrojan.Win32.Z.Kryptik.339800.H
TencentWin32.Trojan.Falsesign.Woqh
Ad-AwareTrojan.GenericKD.36095964
SophosMal/Generic-R + Mal/BadCert-Gen
ComodoMalware@#1szqnttaaw8b3
F-SecureTrojan.TR/Crypt.Agent.njpgm
ZillyaTrojan.RTM.Win32.4329
TrendMicroTROJ_FRS.0NA103AD21
McAfee-GW-EditionDrixed-FJZ!63AFCA355ABC
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
JiangminTrojan.Banker.RTM.wu
AviraTR/Crypt.Agent.njpgm
Antiy-AVLGrayWare/Win32.Kryptik.ehls
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/EmotetCrypt.ARK!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ZoneAlarmTrojan-Banker.Win32.RTM.jfx
GDataTrojan.GenericKD.36095964
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R362882
VBA32Malware-Cryptor.Bambarbiya
ALYacTrojan.Agent.Emotet
MAXmalware (ai score=99)
MalwarebytesTrojan.Dridex
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HISQ
RisingTrojan.Kryptik!1.D006 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Dridex.JWPZ!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.27a

How to remove Trojan-Banker.Win32.RTM.jfx?

Trojan-Banker.Win32.RTM.jfx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment