Malware

About “MSIL/ClipBanker.GT” infection

Malware Removal

The MSIL/ClipBanker.GT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/ClipBanker.GT virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Unusual version info supplied for binary

How to determine MSIL/ClipBanker.GT?


File Info:

crc32: F5A7EA30
md5: 23043620b010d5eb3ffe412162ace27e
name: 23043620B010D5EB3FFE412162ACE27E.mlw
sha1: 2a8503182b66482949d408fbad664271a5bc53ad
sha256: cc099b7accbf06134b294405b746fe22d8611830335231bef35e31116932fc6d
sha512: 815e81ce1655a3a8b9a9eb479a6a2ddce91da0aa000f5aee024f39e63a2de4ebb2bb3875e4a1beade80959ab828ccf727f94d99286507facbe8957724769720d
ssdeep: 96:0uwMtwJ2n6lF+9zGZuIdqdTSPgcVAGECCyOqDIgTOUpfeDgDINzTIMckR6D:0EeSHIdqT3RVyyj2UNPJ3s
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Microsoftxae Windowsxae Operating System $
Assembly Version: 8.5.1.6
InternalName: Cryptocurrencytest.exe
FileVersion: 2.1.6.1
CompanyName: dllhost.exe
LegalTrademarks: COM Surrogate
Comments: COM
ProductName: xa9 Microsoft Corporation. All rights reserved 2018
ProductVersion: 2.1.6.1
FileDescription: Microsoft Corporations
OriginalFilename: Cryptocurrencytest.exe

MSIL/ClipBanker.GT also known as:

K7AntiVirusTrojan ( 0053c8961 )
LionicTrojan.MSIL.Fsysna.4!c
DrWebTrojan.MulDrop8.39214
ALYacGen:Variant.Ursu.295860
CylanceUnsafe
ZillyaTrojan.Fsysna.Win32.15900
SangforTrojan.MSIL.Fsysna.gen
AlibabaTrojan:MSIL/Fsysna.756fab6d
K7GWTrojan ( 0053c8961 )
Cybereasonmalicious.0b010d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ClipBanker.GT
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Fsysna.gen
BitDefenderGen:Variant.Ursu.295860
NANO-AntivirusTrojan.Win32.Fsysna.fhqiyi
MicroWorld-eScanGen:Variant.Ursu.295860
TencentMsil.Trojan.Fsysna.Hnay
Ad-AwareGen:Variant.Ursu.295860
SophosMal/Generic-S
ComodoMalware@#1kfbe66rxlrtw
BitDefenderThetaGen:NN.ZemsilCO.34110.am0@aitUT7d
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Ursu.295860
EmsisoftGen:Variant.Ursu.295860 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.2837DFC
MicrosoftTrojan:MSIL/Upadter.A
GDataGen:Variant.Ursu.295860
McAfeeArtemis!23043620B010
MAXmalware (ai score=100)
PandaTrj/GdSda.A
IkarusTrojan.MSIL.ClipBanker
FortinetMSIL/ClipBanker.GT!tr
AVGWin32:TrojanX-gen [Trj]

How to remove MSIL/ClipBanker.GT?

MSIL/ClipBanker.GT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment