Trojan

Trojan-Banker.Win32.ClipBanker.bi removal instruction

Malware Removal

The Trojan-Banker.Win32.ClipBanker.bi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.ClipBanker.bi virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs

How to determine Trojan-Banker.Win32.ClipBanker.bi?


File Info:

crc32: 3BD3EEF1
md5: 204f461210c09943f761a1ea22b5a730
name: 204F461210C09943F761A1EA22B5A730.mlw
sha1: 2528d54221153481b87582f8b31342eed3257954
sha256: 6b23d4d2a773cb4252be8c039d35092818a5038a1766bb3c7c7beef28064ee62
sha512: a051596d18d7d01408b3b07e1b2e6f31b94e19936d92fe28cf2d605badb571ef81a701b1d6700f57fb98c63a51091febec7d5ef7663ff175724ca6ae63c94864
ssdeep: 6144:JGkPLsYW02QnZlmR75Yi2X3IQCn3fjA9VZFzUxXOdy/KkicWM+5nvwv:JGwc026ZlmR70Y/k9VS+LPMd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 1999-2016 Igor Pavlov
InternalName: 7zFM
FileVersion: 16.02
CompanyName: Igor Pavlov
ProductName: 7-Zip
ProductVersion: 16.02
FileDescription: 7-Zip File Manager
OriginalFilename: 7zFM.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.ClipBanker.bi also known as:

K7AntiVirusTrojan ( 00531b451 )
CynetMalicious (score: 99)
ALYacTrojan.BackSwap.A
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.164741
SangforTrojan.Win32.ClipBanker.bi
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.40417944
K7GWTrojan ( 00531b451 )
Cybereasonmalicious.210c09
ESET-NOD32Win32/BackSwap.A
APEXMalicious
ClamAVWin.Trojan.Backswap-6564636-0
KasperskyTrojan-Banker.Win32.ClipBanker.bi
AlibabaTrojanBanker:Win32/ClipBanker.f932c0b1
NANO-AntivirusTrojan.Win32.ClipBanker.fhowoz
ViRobotTrojan.Win32.S.BackSwap.510976
MicroWorld-eScanTrojan.GenericKD.40417944
TencentWin32.Trojan-banker.Clipbanker.Hnlf
Ad-AwareTrojan.GenericKD.40417944
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.BACKSWAP.SM3
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.gh
FireEyeTrojan.GenericKD.40417944
WebrootW32.Malware.Gen
AviraTR/AD.Swrort.zerxz
Antiy-AVLTrojan[Banker]/Win32.ClipBanker
MicrosoftTrojan:Win32/Bulta!rfn
ArcabitTrojan.Generic.D268BA98
AegisLabTrojan.Win32.ClipBanker.4!c
ZoneAlarmTrojan-Banker.Win32.ClipBanker.bi
GDataTrojan.GenericKD.40417944
AhnLab-V3Malware/Win32.Generic.C2482787
MAXmalware (ai score=99)
VBA32TrojanBanker.ClipBanker
MalwarebytesTrojan.Script
PandaTrj/CI.A
TrendMicro-HouseCallTrojanSpy.Win32.BACKSWAP.SM3
RisingTrojan.ClipBanker!8.5FB (CLOUD)
YandexTrojan.PWS.ClipBanker!+35GFhbZ1DE
IkarusTrojan-Banker.Backswap
FortinetW32/BackSwap.A!tr
Paloaltogeneric.ml

How to remove Trojan-Banker.Win32.ClipBanker.bi?

Trojan-Banker.Win32.ClipBanker.bi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment