Trojan

Should I remove “Trojan-Banker.Win32.ClipBanker.jhq”?

Malware Removal

The Trojan-Banker.Win32.ClipBanker.jhq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.ClipBanker.jhq virus can do?

  • Drops a binary and executes it
  • The executable is likely packed with VMProtect
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Banker.Win32.ClipBanker.jhq?


File Info:

crc32: CD1D9282
md5: 406206000f0e2c4e55e625b3842042d5
name: setup_c.exe
sha1: 44bf5d3b8eac71b09d79ea16920b0b9f95b8d35b
sha256: cde705e283087443cb31f24aeb6669d796692f0057ed7ab240d2e3d39cde98b7
sha512: 51b3d2526b8e0b1415ef88f740f1aa2e57e4cf1d693d0aa3d9ae484ec726eb17f78415497472e4a245a32ff9f1cc68205ccf9c2256740b831a2620d99e6c5c16
ssdeep: 24576:UAHnh+eWsNvskA4RV1Hom2KXImna2jmgJ1XPQAv6O8zmTOcgSLFvDHHaz7l6R:jh+ZkldoPK4Ma2jVQ/BRPM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2017 Dolby Laboratories, Inc. All rights reserved.
InternalName: Dolby DAX2 Tray Icon
FileVersion: 0.8.6.75
CompanyName: Dolby Laboratories, Inc.
Comments: DolbyDAX2TrayIcon
ProductName: DolbyDAX2TrayIcon
ProductVersion: 0.8.6.75
FileDescription: DolbyDAX2TrayIcon
OriginalFilename: DolbyDAX2TrayIcon.exe
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.ClipBanker.jhq also known as:

DrWebTrojan.Siggen9.10503
MicroWorld-eScanGen:Variant.Ursu.754792
FireEyeGeneric.mg.406206000f0e2c4e
Qihoo-360Generic/HEUR/QVM20.1.2B19.Malware.Gen
McAfeeArtemis!406206000F0E
MalwarebytesTrojan.ClipBanker.AutoIt
SangforMalware
BitDefenderGen:Variant.Ursu.754792
Cybereasonmalicious.b8eac7
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataWin32.Trojan.QuilMiner.SYUNRH
KasperskyTrojan-Banker.Win32.ClipBanker.jhq
AegisLabTrojan.Win32.Malicious.4!c
RisingTrojan.Obfus/Autoit!1.BD86 (CLASSIC)
Endgamemalicious (high confidence)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
Trapminemalicious.moderate.ml.score
IkarusTrojan-Spy.HawkEye
WebrootW32.Trojan.Gen
MicrosoftTrojan:Win32/Wacatac.D!ml
ZoneAlarmTrojan-Banker.Win32.ClipBanker.jhq
Acronissuspicious
MAXmalware (ai score=84)
Ad-AwareGen:Variant.Ursu.754792
YandexTrojan.AvsArher.bS9LKk
FortinetAutoIt/Packed.KY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan-Banker.Win32.ClipBanker.jhq?

Trojan-Banker.Win32.ClipBanker.jhq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment