Trojan

About “Trojan.CryptoClipper” infection

Malware Removal

The Trojan.CryptoClipper is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.CryptoClipper virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.CryptoClipper?


File Info:

crc32: E8D2CCC0
md5: 2d3a0180b9671f7af72af065a06d40a6
name: 2D3A0180B9671F7AF72AF065A06D40A6.mlw
sha1: c0f6500c666a56017dc6ce26389b09af682c2f07
sha256: f3b6e8c7ce8d24ff82ff36cfe6df1dce548bc67d5271fa7903c3054039b844f6
sha512: 5829226029360a57e986c9dc921d5c005a0676ca7b32aed7b520b1370b37bf49f1740ae10fe9cf3e072e0073c8c1712f19eead3b5cce0eeff32291eae88a0660
ssdeep: 192:KHetY+x3s1MihfWU2hfE6J59mOvJW4GT0vqAluWfijY8:K+tY+x3s1MMW/dE6j9mOxwTcuWK
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
Assembly Version: 23.1.0.61262
InternalName: Runtime Broker.exe
FileVersion: 23.1.0.61262
CompanyName: Microsoft Corporation
LegalTrademarks:
Comments: Runtime Broker
ProductName:
ProductVersion: 23.1.0.61262
FileDescription: Runtime Broker
OriginalFilename: Runtime Broker.exe

Trojan.CryptoClipper also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CylanceUnsafe
Cybereasonmalicious.0b9671
ESET-NOD32a variant of MSIL/ClipBanker.VJ
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
BitDefenderGen:Variant.Bulz.278796
MicroWorld-eScanGen:Variant.Bulz.278796
Ad-AwareGen:Variant.Bulz.278796
BitDefenderThetaGen:NN.ZemsilF.34692.am0@ay@jCLl
FireEyeGen:Variant.Bulz.278796
EmsisoftGen:Variant.Bulz.278796 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1137599
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Bulz.278796
AhnLab-V3Malware/Win32.RL_Generic.C4327427
MAXmalware (ai score=81)
MalwarebytesTrojan.CryptoClipper
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan.CryptoClipper?

Trojan.CryptoClipper removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment