Trojan

Trojan-Banker.Win32.ClipBanker.gys removal instruction

Malware Removal

The Trojan-Banker.Win32.ClipBanker.gys is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.ClipBanker.gys virus can do?

  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Uses suspicious command line tools or Windows utilities

Related domains:

yip.su
apps.identrust.com
isrg.trustid.ocsp.identrust.com
ocsp.int-x3.letsencrypt.org

How to determine Trojan-Banker.Win32.ClipBanker.gys?


File Info:

crc32: 44DEED6C
md5: 49693bcc918f1771ca48605f1ab953fb
name: ttl.exe
sha1: 5d08c5d9ab95b8ea6161223eeca2a5fef3053235
sha256: f619386a09c87a02717d9393f56cda5755902b5ab91ead9cf135e6e6120d6093
sha512: cb31c513482bee5f92872ae9ba94f3cbbf042da4706cdbdb335043ccd2d4a84eed305ba801fb7de6fcf9cfcbe94a408d5910f85e32ca8b89a1a5675d9e030323
ssdeep: 24576:BAHnh+eWsN3skA4RV1Hom2KXMmHaIhcECtzToa5:Yh+ZkldoPK8YaIGECtF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: PushPrinterConnections.exe
FileVersion: 2.4.7.8
CompanyName: XPS to GDI Converter
Comments: AaQgTZYGkv8ZFvhIAgItWaAMsgsfidhG67CKXoB9PliazSoSXQb7cPWC5GA
ProductVersion: 2.4.7.8
FileDescription: NPS Pipeline
OriginalFilename: PushPrinterConnections.exe
Translation: 0x0809 0x04b0

Trojan-Banker.Win32.ClipBanker.gys also known as:

MicroWorld-eScanTrojan.GenericKD.32769716
FireEyeGeneric.mg.49693bcc918f1771
McAfeePacked-FXF!49693BCC918F
ALYacTrojan.GenericKD.32769716
MalwarebytesTrojan.ClipBanker.AutoIt.Generic
AegisLabTrojan.Win32.ClipBanker.7!c
SangforMalware
K7AntiVirusTrojan ( 005451b51 )
BitDefenderTrojan.GenericKD.32769716
K7GWTrojan ( 005451b51 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.AutoIt.TP
TrendMicro-HouseCallTROJ_GEN.R057C0PKR19
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.32769716
KasperskyTrojan-Banker.Win32.ClipBanker.gys
AlibabaPacked:Application/AutoIt.9c329867
NANO-AntivirusTrojan.Win32.Dwn.gjuibl
RisingTrojan.Obfus/Autoit!1.BD86 (CLASSIC)
Endgamemalicious (high confidence)
F-SecureHeuristic.HEUR/AGEN.1036560
DrWebTrojan.DownLoader30.45329
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
APEXMalicious
CyrenW32/Trojan.MQQX-6586
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1036560
ArcabitTrojan.Generic.D1F406B4
ZoneAlarmTrojan-Banker.Win32.ClipBanker.gys
MicrosoftTrojan:Win32/Tiggre!rfn
Acronissuspicious
MAXmalware (ai score=88)
Ad-AwareTrojan.GenericKD.32769716
CylanceUnsafe
PandaTrj/CI.A
IkarusTrojan.Win32.Autoit
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Packed.KY!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Trojan.234

How to remove Trojan-Banker.Win32.ClipBanker.gys?

Trojan-Banker.Win32.ClipBanker.gys removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment