Trojan

Trojan-Banker.Win32.CliptoShuffler.atn malicious file

Malware Removal

The Trojan-Banker.Win32.CliptoShuffler.atn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.CliptoShuffler.atn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Japanese
  • The binary likely contains encrypted or compressed data.
  • Detects SunBelt Sandbox through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
tldrbox.top
shaefpiapfejigguhfp.ru

How to determine Trojan-Banker.Win32.CliptoShuffler.atn?


File Info:

crc32: 61F12AE9
md5: 68f03fc24e2a10579e259b3e60edf593
name: 11.exe
sha1: 6795977b6e5fe309c0f2a1c517d4f7e6ea250586
sha256: a9e8cc04eb20306734cbb0aaed90746f2e87260a1d66f20413efdf1c331fe0b0
sha512: 9887d027c45aaaac7c33d4c673465f81529e677ec3685a89248f8438946c8fff08a7cb1058fa97bea2e5e0e3eb922a7d836634f741fdffd43c3795901c0fe778
ssdeep: 3072:0EAIO2nv//xSP6ix+dYjagRP7BNR85bYtEdu6Ll:0EAI1vxe6dkt+Ye
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.Win32.CliptoShuffler.atn also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33534238
Qihoo-360Generic/HEUR/QVM10.2.CCFD.Malware.Gen
McAfeeArtemis!68F03FC24E2A
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderTrojan.GenericKD.33534238
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecRansom.Nemty
ESET-NOD32a variant of Win32/Kryptik.HBVR
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.CliptoShuffler.atn
AlibabaTrojan:Win32/Starter.ali2000005
SUPERAntiSpywareRansom.GandCrab/Variant
TencentWin32.Trojan-banker.Cliptoshuffler.Wske
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33534238 (B)
DrWebTrojan.Siggen9.19740
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FortinetW32/Kryptik.HBSU!tr
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.68f03fc24e2a1057
SophosMal/RyPack-A
IkarusTrojan.Win32.Crypt
WebrootW32.Ransom.Ryuk
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D1FFB11E
ViRobotTrojan.Win32.Z.Rypack.161792
ZoneAlarmTrojan-Banker.Win32.CliptoShuffler.atn
MicrosoftTrojan:Win32/Bandit.GC!MTB
AhnLab-V3Trojan/Win32.MalPe.R328248
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34100.juW@ayL85QdG
ALYacTrojan.GenericKD.33534238
VBA32BScope.Trojan.AET.281105
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.Kryptik!8.8 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_95%
GDataTrojan.GenericKD.33534238
Ad-AwareTrojan.GenericKD.33534238
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Banker.Win32.CliptoShuffler.atn?

Trojan-Banker.Win32.CliptoShuffler.atn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment