Malware

ClipBanker.215 (B) removal guide

Malware Removal

The ClipBanker.215 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ClipBanker.215 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

when.legtest.bid
wake.tendencyrhythm.bid

How to determine ClipBanker.215 (B)?


File Info:

crc32: 48E04C99
md5: a4ca362f85a4819726045e56f0c09ded
name: A4CA362F85A4819726045E56F0C09DED.mlw
sha1: 02e8aa1fbcb2d351dd2d6198dd8e9e5fdec96905
sha256: 50fca792555d5740a53d550c08842cb1c4b164aa6049eab089242781c57f5dba
sha512: 28145d2c1cea509326936b2a49011631cec135463b5e958ce0ef3c98925690048f6c3de8809834f767164b384f0ab07ea31df188d7c085215452713c4ac75efb
ssdeep: 12288:YtENWEYjyWPnOsoja6S7oSEMwDgIJ3745Oa:6EYjyWPnojhSM4wDgQ3745O
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017
InternalName: TemplatelExeFile.rc
FileVersion: 1.0.0.1
CompanyName: TODO:
ProductName: TODO:
ProductVersion: 1.0.0.1
FileDescription: TODO:
OriginalFilename: TemplatelExeFile.rc
Translation: 0x0419 0x04b0

ClipBanker.215 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.ClipBanker.215
FireEyeGeneric.mg.a4ca362f85a48197
CAT-QuickHealSwBundler.Prepscram.EMU.Y7
ALYacGen:Variant.ClipBanker.215
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabAdware.Win32.Generic.2!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00528e801 )
BitDefenderGen:Variant.ClipBanker.215
K7GWTrojan ( 0050eca01 )
Cybereasonmalicious.f85a48
CyrenW32/S-4ce797cb!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Evo-gen [Susp]
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
AlibabaTrojan:Win32/Kryptik.d267df5c
NANO-AntivirusRiskware.Win32.StartSurf.ephkxd
RisingTrojan.Kryptik!1.AB1C (CLASSIC)
Ad-AwareGen:Variant.ClipBanker.215
EmsisoftGen:Variant.ClipBanker.215 (B)
ComodoApplication.Win32.IStartSurf.BS@7lng48
F-SecureHeuristic.HEUR/AGEN.1103317
ZillyaAdware.StartSurf.Win32.11782
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosGeneric PUA AC (PUA)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.fzpr
AviraHEUR/AGEN.1103317
eGambitUnsafe.AI_Score_99%
Antiy-AVLGrayWare[AdWare]/Win32.AGeneric
MicrosoftSoftwareBundler:Win32/Prepscram
ArcabitTrojan.ClipBanker.215
SUPERAntiSpywarePUP.Bundler/Variant
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
GDataGen:Variant.ClipBanker.215
AhnLab-V3PUP/Win32.StartSurf.R201639
Acronissuspicious
McAfeePUP-XBQ-UU
MAXmalware (ai score=88)
VBA32BScope.AdWare.StartSurf
MalwarebytesGeneric.Trojan.Bundler.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.FSSN
TencentMalware.Win32.Gencirc.10b3a151
YandexTrojan.GenAsa!Oktj2z3Be/Q
IkarusAdWare.ICLoader
MaxSecureTrojan.Malware.3771246.susgen
FortinetW32/Kryptik.FTMV!tr
BitDefenderThetaGen:NN.ZexaF.34590.Gy0@amzDGVak
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
Qihoo-360Win32/Adware.Generic.HgIASOYA

How to remove ClipBanker.215 (B)?

ClipBanker.215 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment