Trojan

Trojan:Win32/LaplasClipper.C!MTB removal guide

Malware Removal

The Trojan:Win32/LaplasClipper.C!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/LaplasClipper.C!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/LaplasClipper.C!MTB?


File Info:

name: CBC4C5EF56CC6792D8EA.mlw
path: /opt/CAPEv2/storage/binaries/ae7aa93a03654944fbbc58868688c65991df801afdd5d98ff9fdb6e58e22d6f2
crc32: 0814E8EE
md5: cbc4c5ef56cc6792d8ea94e0212e1ab8
sha1: 30d43c1ca0cce4f972fb7f3d16b1f85b9f9a3dcf
sha256: ae7aa93a03654944fbbc58868688c65991df801afdd5d98ff9fdb6e58e22d6f2
sha512: b047a4ef53061e81b48b52220cbb482418d588edd18dfcec23dd1213e023b21add204f160d02d024004e39123f7f1f1b47458743108753c936236fe4119e56f5
ssdeep: 6144:R3BAjZVcoYrQAnHHAOCvkjyZkkGrcAl7:1BAjZySWHgk+O7
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16B456D8F927C422FD062B838269463A98715DFC1025DEAD652BCB67D3EE035059FE738
sha3_384: a3851fa93ed90f3d77bceb85b4f6d665e0f3905e1db57a01143ef6491f31741bb12f73c73817b1d7ca776879e81a867b
ep_bytes: e8db050000e974feffff558bec8b4508
timestamp: 2023-05-18 13:10:32

Version Info:

0: [No Data]

Trojan:Win32/LaplasClipper.C!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.344335
McAfeeArtemis!CBC4C5EF56CC
MalwarebytesGeneric.Crypt.Trojan.DDS
VIPREGen:Variant.Lazy.344335
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a58ff1 )
AlibabaTrojanSpy:Win32/Stealer.1433ed8f
K7GWTrojan ( 005a58ff1 )
BitDefenderThetaGen:NN.ZexaF.36250.mvW@aGTQPwk
VirITTrojan.Win32.GenusT.DIQO
CyrenW32/Agent.GIY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HTNR
APEXMalicious
ClamAVWin.Packed.Lazy-10002615-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Lazy.344335
AvastWin32:CrypterX-gen [Trj]
TencentMalware.Win32.Gencirc.11a10aa5
EmsisoftGen:Variant.Lazy.344335 (B)
F-SecureTrojan.TR/AD.RedLineSteal.jrfgh
DrWebTrojan.PWS.Stealer.35843
ZillyaTrojan.Kryptik.Win32.4203902
TrendMicroTROJ_GEN.R002C0DEJ23
McAfee-GW-EditionBehavesLike.Win32.Generic.tz
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.cbc4c5ef56cc6792
SophosTroj/Steal-DNX
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.6MFG3C
GoogleDetected
AviraTR/AD.RedLineSteal.jrfgh
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Lazy.D5410F
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/LaplasClipper.C!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5429484
Acronissuspicious
ALYacGen:Variant.Lazy.344335
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DEJ23
RisingBackdoor.Agent!8.C5D (TFE:5:JhgDhzyiBkO)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.73793603.susgen
FortinetW32/Kryptik.HTNR!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/LaplasClipper.C!MTB?

Trojan:Win32/LaplasClipper.C!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment