Trojan

Trojan-Banker.Win32.ClipBanker.lw removal guide

Malware Removal

The Trojan-Banker.Win32.ClipBanker.lw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.ClipBanker.lw virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Creates a copy of itself

How to determine Trojan-Banker.Win32.ClipBanker.lw?


File Info:

name: A1C24361ED7B210C871A.mlw
path: /opt/CAPEv2/storage/binaries/134cd65d7b021e912b6815c2eb981dfc5bd0b39381b6bc05c91d8d2b57dd85e6
crc32: E4A1C555
md5: a1c24361ed7b210c871aec263c70c6f7
sha1: 637703002b57067ae9f9c575f18a70fb569a5a85
sha256: 134cd65d7b021e912b6815c2eb981dfc5bd0b39381b6bc05c91d8d2b57dd85e6
sha512: e9108e51d10878cea278672b71446cc42c91b9a04967c13a89b454a79811804c885592a6312922c899df62b1d642bd965d649d94c05e7e0509529cd6372a853c
ssdeep: 6144:vkgNbug/UYd38l7xT2icWEwktiNAXcLoaQHqvceXcj+MK5T7QGnR5pDDSTQI3+cg:VSgs+s3TRPzGgwqvcIcahT7jScMHg/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199B45C15E3A867EECD32AF384A274D585E2DAD7B3734164DEF941C780A35382E0953E2
sha3_384: a7fa3f84bbbdb1ece98e68f4cc9d430ae1f1aba47abd088103987fa29c7445b700f25c9885f89250061a8dce0f6ffd8e
ep_bytes: 558bec83c4f0b88c514500e8c809fbff
timestamp: 1992-06-19 22:22:17

Version Info:

FileVersion: 1.1.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.ClipBanker.lw also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.ClipBanker.4!c
MicroWorld-eScanGen:Variant.Doina.15857
FireEyeGeneric.mg.a1c24361ed7b210c
McAfeeArtemis!A1C24361ED7B
Cylanceunsafe
ZillyaDropper.Agent.Win32.374690
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00532ff21 )
AlibabaTrojanBanker:Win32/ClipBanker.2d8d6736
K7GWTrojan ( 00532ff21 )
Cybereasonmalicious.1ed7b2
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Delf.TYB
APEXMalicious
KasperskyTrojan-Banker.Win32.ClipBanker.lw
BitDefenderGen:Variant.Doina.15857
NANO-AntivirusTrojan.Win32.Drop.fczyqp
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b3b94c
EmsisoftGen:Variant.Doina.15857 (B)
DrWebTrojan.MulDrop9.4175
VIPREGen:Variant.Doina.15857
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
WebrootW32.Trojan.Gen
Antiy-AVLTrojan[Dropper]/Win32.Agent
MicrosoftTrojan:Win32/Pynamer.A!rfn
XcitiumMalware@#2k6h5ys5zbsbk
ArcabitTrojan.Doina.D3DF1
ZoneAlarmTrojan-Banker.Win32.ClipBanker.lw
GDataGen:Variant.Doina.15857
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2552628
BitDefenderThetaGen:NN.ZelphiF.36348.EG0@a8Ru9Jpi
ALYacGen:Variant.Doina.15857
VBA32TScope.Trojan.Delf
MalwarebytesNeshta.Virus.FileInfector.DDS
PandaTrj/CI.A
RisingTrojan.Delf!8.67 (CLOUD)
YandexTrojan.GenAsa!RqXD7aE+PFk
IkarusTrojan.Win32.Delf
MaxSecureTrojan.Malware.74013181.susgen
FortinetW32/Delf.TYB!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan-Banker.Win32.ClipBanker.lw?

Trojan-Banker.Win32.ClipBanker.lw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment