Malware

MSIL/ClipBanker.GM information

Malware Removal

The MSIL/ClipBanker.GM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/ClipBanker.GM virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Serbian (Latin)
  • Authenticode signature is invalid

How to determine MSIL/ClipBanker.GM?


File Info:

name: DC94AB73EADB420E3626.mlw
path: /opt/CAPEv2/storage/binaries/ffeeb844993f2fee324a19467d8ed8a36d82084002542674b1f3ee111ca0e643
crc32: 53AF9E89
md5: dc94ab73eadb420e362697dfdea306a7
sha1: fdcf1d67eb22b0fac6cb598d0a138c63b79fb0bf
sha256: ffeeb844993f2fee324a19467d8ed8a36d82084002542674b1f3ee111ca0e643
sha512: 88ccc83900bf4703786945f90dcf1352bb48d76b5ced4c481b20d3dccd0566cf93336741b3b419a1b0da2a96f8a29f401d78a1e9ad22eee99d52b03ef9728011
ssdeep: 3072:SzEWN5IyOrM2MrIfjblaX/g7q0LyejLl77W8rOirJTqX2wA2j8/VE:SxIyTIfj5aW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T157A3B584BBF8561EF9F34F71A9F152025961FC12AD33E39E6481339E0C756844A1ABF2
sha3_384: b7e37ae4b95f2e2d08e441e8cd392dcc7e07bcac6c9aaafadb4746ada517df6d9b7680f659a25ac592833cd0dd2d2601
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-12-04 17:16:50

Version Info:

CompanyName: Realtek Semiconductor
FileDescription: Realtek HD audio menadžer
FileVersion: 1.0.657.0
InternalName: RtkNGui.exe
LegalCopyright: 2017 (c) Realtek Semiconductor. All rights reserved.
OriginalFilename: RtkNGui.exe
ProductName: Realtek HD audio menadžer
ProductVersion: 1.0.657.0
Translation: 0x0419 0x04e4

MSIL/ClipBanker.GM also known as:

LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILPerseus.160621
FireEyeGeneric.mg.dc94ab73eadb420e
McAfeeRDN/Generic Dropper
CylanceUnsafe
ZillyaDropper.Agent.Win32.384915
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0053b15a1 )
BitDefenderGen:Variant.MSILPerseus.160621
K7GWTrojan ( 0053b15a1 )
Cybereasonmalicious.3eadb4
BitDefenderThetaGen:NN.ZemsilF.34084.gm0@aK1aVu5P
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ClipBanker.GM
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Dropper.Win32.Agent.gen
AlibabaTrojanDropper:MSIL/ClipBanker.6c5f0219
NANO-AntivirusTrojan.Win32.ClipBanker.fmppdv
Ad-AwareGen:Variant.MSILPerseus.160621
SophosMal/Generic-S
ComodoMalware@#1qpneze4zz7xk
DrWebTrojan.DownLoader27.24549
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic Dropper
EmsisoftGen:Variant.MSILPerseus.160621 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1121253
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.29C35A6
MicrosoftTrojan:Win32/Occamy.CFF
GDataGen:Variant.MSILPerseus.160621
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Infostealer.R210957
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.MSILPerseus.160621
PandaTrj/GdSda.A
TencentWin32.Trojan-dropper.Agent.Wugy
YandexTrojan.ClipBanker!IkiRx+ZBB0o
IkarusTrojan.MSIL.ClipBanker
FortinetW32/Agent.GM!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove MSIL/ClipBanker.GM?

MSIL/ClipBanker.GM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment