Trojan

Trojan-Banker.Win32.ClipBanker.hkd removal instruction

Malware Removal

The Trojan-Banker.Win32.ClipBanker.hkd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.ClipBanker.hkd virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Code injection with CreateRemoteThread in a remote process
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

How to determine Trojan-Banker.Win32.ClipBanker.hkd?


File Info:

crc32: AD54E7FD
md5: fd33ffb0420bed209a5a49de4f683fb6
name: calcul-assemblage-par-pointes-bois-bois.exe
sha1: c0c752d8ed242e1614773974d88439aab277f73a
sha256: af85c39df4372ba69b675baba500e5bfd7920edb6931d5177e68da8130b46721
sha512: 4bfb7b2843f671275bc0d354a8cb2151e94fb2f3c0edf07339c0c6eb1158221845356fbf29ce8a56ba3cc7252a5f3de24eea23c0b5d815bc6be6340eb15c1dc0
ssdeep: 24576:w5o8ex/qOHT3a+9/2bKM1pjvmHK269XpYj7XrfFPlzfVLGl60dvjWLjgA7OqcZ:MoX/7HTCXvKK2oXK7txVKl6MjWLcA7de
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: Application
FileVersion: 2, 0, 0, 7
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName:
SpecialBuild:
ProductVersion: 2, 0, 0, 7
FileDescription: Application
OriginalFilename: Application
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.ClipBanker.hkd also known as:

DrWebAdware.SafeSurf.63
FireEyeGeneric.mg.fd33ffb0420bed20
CAT-QuickHealTrojan.Riskware
McAfeeGenericRXEO-MI!FD33FFB0420B
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.8ed242
TrendMicroTROJ_GEN.R002C0PJM19
BitDefenderThetaGen:NN.ZexaF.33558.pr0@aWZLfOdi
SymantecTrojan.Gen
AvastWin32:Malware-gen
KasperskyTrojan-Banker.Win32.ClipBanker.hkd
AlibabaTrojan:Application/Generic.43e78acf
NANO-AntivirusTrojan.Win32.SafeSurf.eqknrt
RisingTrojan.Generic@ML.100 (RDMK:FKFzNRSx6K2MEigx3Mcg3Q)
SophosMal/Generic-S
ComodoMalware@#momv1di78uq0
F-SecureTrojan.TR/Agent.1302528.60
ZillyaTrojan.Agent.Win32.812892
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
Trapminemalicious.high.ml.score
CMCTrojan-Dropper.Win32.Injector!O
IkarusTrojan-Dropper.Win32.Injector
JiangminTrojanDropper.Injector.alwb
WebrootW32.Malware.Gen
AviraTR/Agent.1302528.60
Antiy-AVLTrojan[Dropper]/Win32.Injector
Endgamemalicious (high confidence)
ZoneAlarmTrojan-Banker.Win32.ClipBanker.hkd
MicrosoftTrojan:Win32/Occamy.C
VBA32Adware.SafeSurf
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PJM19
YandexTrojan.DR.Injector!OTNUTx7MkSw
eGambitGeneric.Malware
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Win32/Trojan.ad7

How to remove Trojan-Banker.Win32.ClipBanker.hkd?

Trojan-Banker.Win32.ClipBanker.hkd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment