Trojan

How to remove “Trojan-Banker.PowerShell.ClipBanker”?

Malware Removal

The Trojan-Banker.PowerShell.ClipBanker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.PowerShell.ClipBanker virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan-Banker.PowerShell.ClipBanker?


File Info:

name: A6B3DB3C30FA3C4379C6.mlw
path: /opt/CAPEv2/storage/binaries/fc196df1c1b1de602ff609ab1af5338a576aef866389e80463a76f94564ed7a8
crc32: CBE84EDE
md5: a6b3db3c30fa3c4379c6bac463d58a6b
sha1: 67e9f45057e85e246cb60bb9d92df9bda551fd9e
sha256: fc196df1c1b1de602ff609ab1af5338a576aef866389e80463a76f94564ed7a8
sha512: 9b5c77b16b01c692c5391821fe7723d5f50ae26b957391548968fffcef23b1477ce215c6d6826570604876c6ff5930d7c4a872820463eecf65ea28af13281de0
ssdeep: 6144:sq2gGDjEyXqBT5Q2b2dy8LV5Hx0phPuC8o:sq2gGPSbyLapH8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160445A2439E9403FF1B79FF12BD069E6B969F2FE2707A556247007CB4B41A10DE4263A
sha3_384: 3b7f3ed5687080a27a890f7ec084ab808896cf358d191e004ecb567ececc8bf6e11e487f40d90e2c9ba5f433252f165c
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-18 01:17:06

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: run.exe
LegalCopyright:
OriginalFilename: run.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan-Banker.PowerShell.ClipBanker also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.49351504
FireEyeGeneric.mg.a6b3db3c30fa3c43
McAfeeArtemis!A6B3DB3C30FA
CylanceUnsafe
VIPRETrojan.GenericKD.49351504
SangforBanker.Win32.Clipbanker.Vrea
K7AntiVirusTrojan ( 005947b11 )
AlibabaTrojanBanker:Win32/ClipBanker.2325e44f
K7GWTrojan ( 005947b11 )
Cybereasonmalicious.057e85
CyrenW32/ABRisk.CIPZ-2192
SymantecML.Attribute.HighConfidence
ESET-NOD32PowerShell/Agent.GZ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Detected-9956421-0
KasperskyHEUR:Trojan-Banker.PowerShell.ClipBanker.gen
BitDefenderTrojan.GenericKD.49351504
NANO-AntivirusTrojan.Win32.PowerShell.jpqjyv
AvastWin32:Trojan-gen
TencentWin32.Trojan-banker.Clipbanker.Lnxr
Ad-AwareTrojan.GenericKD.49351504
EmsisoftTrojan.GenericKD.49351504 (B)
ComodoMalware@#3ed41r1uopxar
TrendMicroTROJ_GEN.R002C0WFQ22
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataMSIL.Trojan.PSE.R4KKU7
JiangminTrojan.Banker.PowerShell.b
AviraTR/Agent.hpuxv
Antiy-AVLTrojan/Generic.ASMalwS.80D5
KingsoftWin32.Troj.Banker.(kcloud)
GridinsoftRansom.Win32.Wacatac.sa
ZoneAlarmHEUR:Trojan-Banker.PowerShell.ClipBanker.gen
MicrosoftTrojan:Win32/ClipBanker!MSR
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Kryptik.C4779736
ALYacTrojan.GenericKD.49351504
MAXmalware (ai score=80)
MalwarebytesMalware.AI.2504151262
TrendMicro-HouseCallTROJ_GEN.R002C0WFQ22
RisingTrojan.Kryptik!1.DB9C (CLASSIC)
IkarusTrojan.PowerShell.Agent
MaxSecureTrojan.Malware.184562141.susgen
FortinetPossibleThreat
AVGWin32:Trojan-gen
PandaTrj/Chgt.AB
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Banker.PowerShell.ClipBanker?

Trojan-Banker.PowerShell.ClipBanker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment