Trojan

What is “Trojan:Win32/Clustinex!C”?

Malware Removal

The Trojan:Win32/Clustinex!C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Clustinex!C virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/Clustinex!C?


File Info:

name: 908D6DD77EFE957978C2.mlw
path: /opt/CAPEv2/storage/binaries/68e7372bebfebfc68efb38c360e45f43190a97132ace6df8155298e5897c679f
crc32: 1B31E463
md5: 908d6dd77efe957978c241e345f8d956
sha1: ce9b569460e6980bc58efbb8bc99d69dd8af7abb
sha256: 68e7372bebfebfc68efb38c360e45f43190a97132ace6df8155298e5897c679f
sha512: d2c9fbd14d1ff48ee0f9a69e2f3fa50d90df14f26986a3b213f6d8af86b9b2531165181e7beef670275c84d3048c1ea362a189f12fef898ac89cc3609254c575
ssdeep: 98304:bhsgFKPCftISOs+mskZSDEcil6ox1gOe8oRXyZkHs1chKWrwmZi8PW9:dHKKlIvs+msmSDLil6ox1pe3XMkHGchS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135362322F3918437D0221A3D9DAB86B5A53ABF112E38B9877FE81D0D5F386C13915397
sha3_384: 3445475b63d9161ea28039f06676c09b82b0aa2d5ab75b05335fc212bd23fd7548d662b290954ac514f6ce09d44517d5
ep_bytes: 558bec83c4e033c08945e08945ec8945
timestamp: 2010-11-30 02:54:48

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: setup
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

Trojan:Win32/Clustinex!C also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.ProcGMar.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.ProcGMar.3D34F529
FireEyeGeneric.mg.908d6dd77efe9579
SkyhighBehavesLike.Win32.Generic.rc
ALYacGeneric.ProcGMar.3D34F529
Cylanceunsafe
ZillyaDropper.Agent.Win32.65647
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0040f0b61 )
AlibabaTrojanDropper:Win32/Clustinex.fe4be8a2
K7GWTrojan ( 0040f0b61 )
BitDefenderThetaAI:Packer.D7BF6B7719
VirITTrojan.Win32.Generic.BTGS
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDropper.Binder.NCB
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DBL24
AvastWin32:Delf-NZB [Trj]
BitDefenderGeneric.ProcGMar.3D34F529
NANO-AntivirusTrojan.Win32.Delphi.bajriy
TencentMalware.Win32.Gencirc.115399c1
EmsisoftGeneric.ProcGMar.3D34F529 (B)
F-SecureDropper.DR/Delphi.Gen
DrWebTrojan.MulDrop8.2842
VIPREGeneric.ProcGMar.3D34F529
TrendMicroTROJ_GEN.R002C0DBL24
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
MAXmalware (ai score=100)
JiangminTrojanDropper.Agent.axzf
AviraDR/Delphi.Gen
VaristW32/Delf.ST.gen!Eldorado
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/Clustinex.gen!C
XcitiumMalware@#1js998213yylf
ArcabitGeneric.ProcGMar.3D34F529
GDataGeneric.ProcGMar.3D34F529
CynetMalicious (score: 99)
McAfeeGeneric Dropper!dmj
VBA32BScope.TrojanBanker.BestaFera
MalwarebytesBinder.Trojan.Dropper.DDS
PandaTrj/CI.A
RisingDropper.Binder!8.DA (TFE:4:3WYDOA1PGOO)
YandexTrojan.GenAsa!h7WEdh8VSXA
IkarusVirus.Win32.Agent
MaxSecureTrojan.Malware.4389285.susgen
FortinetW32/Dropper.DMJ!tr
AVGWin32:Delf-NZB [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Binder.NCB

How to remove Trojan:Win32/Clustinex!C?

Trojan:Win32/Clustinex!C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment