Malware

About “MSIL/ClipBanker.HD” infection

Malware Removal

The MSIL/ClipBanker.HD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/ClipBanker.HD virus can do?

  • Creates RWX memory
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/ClipBanker.HD?


File Info:

crc32: 6EECF425
md5: 968e57c7f0fed1c269927b328998fde4
name: 968E57C7F0FED1C269927B328998FDE4.mlw
sha1: 27396c65584a3422ee7b2d3e3c787d950c117ce2
sha256: 2dfbcc0d9a4bc010fe75655962236f3d57848c53d302b60874ba45aa8b98080e
sha512: 98c12ce2793151f90114f9d3eff79f09fe82c0e1eb58e548ccb35f72ef008464ba2ab93e630cc03de4feb8b6b114c70ea6010934cd4f36a5b5e03e669f937169
ssdeep: 192:AuQSDh8b9CrvzfHLHLJL2Iz/NVRPpLgLgY0Gm0ydPWe+OB:PQSDYizfHLHLJL2G1VRhLgLgpr0yVW/
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2018
Assembly Version: 1.0.0.0
InternalName: WindowsFormsApplication1.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
ProductName: WindowsFormsApplication1
ProductVersion: 1.0.0.0
FileDescription: WindowsFormsApplication1
OriginalFilename: WindowsFormsApplication1.exe

MSIL/ClipBanker.HD also known as:

K7AntiVirusTrojan ( 0053f3311 )
LionicTrojan.MSIL.RegRun.4!c
ALYacTrojan.GenericKD.40623737
ZillyaTrojan.ClipBanker.Win32.909
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/RegRun.8c8a143d
K7GWTrojan ( 0053f3311 )
Cybereasonmalicious.7f0fed
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ClipBanker.HD
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.RegRun.gen
BitDefenderTrojan.GenericKD.40623737
NANO-AntivirusTrojan.Win32.RegRun.fjlqaj
MicroWorld-eScanTrojan.GenericKD.40623737
TencentWin32.Trojan.Spy.Htvy
Ad-AwareTrojan.GenericKD.40623737
SophosMal/Generic-S
ComodoMalware@#vpnc5edswjzg
BitDefenderThetaGen:NN.ZemsilF.34170.am0@aauqbwm
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.40623737
EmsisoftTrojan.GenericKD.40623737 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.ClipBanker.mlupi
Antiy-AVLTrojan/Generic.ASMalwS.28AAA75
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataTrojan.GenericKD.40623737
McAfeeArtemis!968E57C7F0FE
MAXmalware (ai score=100)
PandaTrj/GdSda.A
YandexTrojan.RegRun!RELzFmm59Mw
IkarusTrojan.MSIL.ClipBanker
FortinetW32/Regrun.HD!tr
AVGWin32:Malware-gen

How to remove MSIL/ClipBanker.HD?

MSIL/ClipBanker.HD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment