Trojan

What is “Trojan-Banker.Win32.ClipBanker”?

Malware Removal

The Trojan-Banker.Win32.ClipBanker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Trojan-Banker.Win32.ClipBanker virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.ClipBanker?


File Info:

crc32: BA6AF679
md5: e1dd89e1c87881db7d560405d63ca9df
name: azo1.exe
sha1: 90d9b05dfe45e2919e44e4e353343b09f78d5a15
sha256: 20e8bd2f9524768f1a911f7f5b4e886d3434fe2cd115ccd62dea8aa4267e1240
sha512: ec6490961b72b5ac544aa588d461c4f21c8c17687feb48a668b72b3a258cb68ac739c4fd52cb26d3cddfb1bd2990a538155d0aa5c78fe48a04cdde012af9e1e3
ssdeep: 6144:dC3sxOzJTNiQZdBGOx+tyqe+3/uZQfdTpa+zxyeU2HCov:gsx6hiQTBZFT0PfpA+zweUtov
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan-Banker.Win32.ClipBanker also known as:

MicroWorld-eScanGen:Variant.Graftor.684155
FireEyeGeneric.mg.e1dd89e1c87881db
McAfeeFareit-FQC!A10DC8160FF8
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Graftor.684155
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.dfe45e
TrendMicroTrojanSpy.Win32.LOKI.SMAD1.hp
BitDefenderThetaGen:NN.ZelphiF.32253.smGfaOqB3ili
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD1.hp
GDataGen:Variant.Graftor.684155
KasperskyHEUR:Trojan-Banker.Win32.ClipBanker.gen
RisingTrojan.Injector!8.C4 (TFE:5:edSHVXX79sR)
Endgamemalicious (moderate confidence)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.dc
Trapminemalicious.high.ml.score
SophosMal/Fareit-V
APEXMalicious
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Graftor.DA707B
ZoneAlarmHEUR:Trojan-Banker.Win32.ClipBanker.gen
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
ALYacGen:Variant.Graftor.684155
MAXmalware (ai score=89)
Ad-AwareGen:Variant.Graftor.684155
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EJCD
FortinetW32/Injector.EESQ!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Banker.Win32.ClipBanker?

Trojan-Banker.Win32.ClipBanker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment