Malware

Win32/ClipBanker.LH malicious file

Malware Removal

The Win32/ClipBanker.LH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/ClipBanker.LH virus can do?

  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/ClipBanker.LH?


File Info:

crc32: DE81FAC6
md5: 56dd2d43f5d0e8192b3e4f242121ac1d
name: 56DD2D43F5D0E8192B3E4F242121AC1D.mlw
sha1: b588a5a7894a697e76327a4b5cf170de6fd7d8c6
sha256: 809ace06ab181f154217a973658e42bae1f3db7d5e8583fbd95a8a2e46f3a755
sha512: a389f3c613871610b35c66fa0fa8a9a3c18101d5b54ca5bb9083918b79f8617527e6c95a8584dc31c97ad59295f013c08c91988e60782e5eec709bd6d8fe4d6f
ssdeep: 384:DUSQo8n/fpJEgK+9a/WI4GSFdr0NA5fLjXEVwHnsRsFel7xI:4BfJJEg8u55fX5HnsRs+7
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/ClipBanker.LH also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.37613
FireEyeGeneric.mg.56dd2d43f5d0e819
Qihoo-360Win32/TrojanSpy.ClipBanker.HxQBKRsA
McAfeeGenericRXAA-AA!56DD2D43F5D0
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056571c1 )
BitDefenderGen:Variant.Fugrafa.37613
K7GWTrojan ( 0056571c1 )
BitDefenderThetaAI:Packer.AC1773961E
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Banker.Win32.ClipBanker.vho
AlibabaTrojanBanker:Win32/ClipBanker.d3e30081
NANO-AntivirusTrojan.Win32.ClipBanker.ikgzxs
AegisLabTrojan.Win32.ClipBanker.7!c
RisingTrojan.ClipBanker!8.5FB (CLOUD)
Ad-AwareGen:Variant.Fugrafa.37613
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1136181
TrendMicroTrojanSpy.Win32.CLIPBANKER.SM
McAfee-GW-EditionBehavesLike.Win32.Dropper.mm
EmsisoftGen:Variant.Fugrafa.37613 (B)
IkarusTrojan.Win32.Clipbanker
JiangminTrojan.Diple.amki
AviraHEUR/AGEN.1136181
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Fugrafa.D92ED
ZoneAlarmHEUR:Trojan-Banker.Win32.ClipBanker.vho
GDataGen:Variant.Fugrafa.37613
AhnLab-V3Malware/Win32.Generic.C3619560
VBA32TrojanBanker.ClipBanker
MalwarebytesTrojan.ClipBanker
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/ClipBanker.LH
TrendMicro-HouseCallTrojanSpy.Win32.CLIPBANKER.SM
TencentWin32.Trojan-banker.Clipbanker.Sxyr
YandexTrojan.ClipBanker!DWUKHrx7Qcg
FortinetW32/PossibleThreat
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.3f5d0e
Paloaltogeneric.ml

How to remove Win32/ClipBanker.LH?

Win32/ClipBanker.LH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment