Malware

MSIL/ClipBanker.PW (file analysis)

Malware Removal

The MSIL/ClipBanker.PW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/ClipBanker.PW virus can do?

  • Anomalous binary characteristics

How to determine MSIL/ClipBanker.PW?


File Info:

crc32: EDDAC281
md5: e290fb8a313ec0ebb8eedeeb325420c4
name: E290FB8A313EC0EBB8EEDEEB325420C4.mlw
sha1: 9c3705ec1412a42f92aff7df739c9ea2800215cb
sha256: b1294420897af7ed238eb612c446ae34dcc12fa88dbd91b3bc4ecf68bf822b02
sha512: 8d9067ccf402ad0abb628ddb391cd0a4ca2f06554db71d2f675ae6e6a813a8ce45d249fac82e2d9086ee605955f342fd0464bd81a1f74428cee2b4d6759030cf
ssdeep: 12288:GgLZL3hBUv5//WJdUiyKqR8JZuecfXQjWIbxnkMmrE/i7yzF:GgLZbhq//yahKqR8JZuecfXybcEkyzF
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: NzfmCxXLD9TPaxc
FileVersion: 6.9.5.0
CompanyName: Mega
LegalTrademarks: qX4_
Comments: l67fuMLtSB0oAgP
ProductName: Chat_Update
ProductVersion: 0.9.2.8
FileDescription: fL-YZb6gvZtcQwx
OriginalFilename: BuildName.exe
Translation: 0x0409 0x04b0

MSIL/ClipBanker.PW also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00568dbc1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen10.44110
CynetMalicious (score: 100)
CAT-QuickHealHackTool.ProcHacker.P5
ALYacGen:Heur.Mint.Porcupine.Lu3@cqklclkig
CylanceUnsafe
ZillyaTrojan.ClipBanker.Win32.5764
SangforSuspicious.Win32.Save.a
AlibabaTrojanBanker:MSIL/ClipBanker.f15f2db2
K7GWTrojan ( 00568dbc1 )
Cybereasonmalicious.a313ec
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ClipBanker.PW
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
BitDefenderGen:Heur.Mint.Porcupine.Lu3@cqklclkig
NANO-AntivirusTrojan.Win32.ClipBanker.ibtcqs
MicroWorld-eScanGen:Heur.Mint.Porcupine.Lu3@cqklclkig
TencentMsil.Trojan-banker.Clipbanker.Ajky
Ad-AwareGen:Heur.Mint.Porcupine.Lu3@cqklclkig
SophosGeneric Reputation PUA (PUA)
ComodoMalware@#1rosxi7xltgvp
BitDefenderThetaGen:NN.ZemsilF.34670.bm0@aqdLjFc
VIPRETrojan.Win32.Generic!BT
TrendMicroPUA.Win32.ProcHack.C
McAfee-GW-EditionBehavesLike.Win32.ICLoader.jc
FireEyeGeneric.mg.e290fb8a313ec0eb
EmsisoftGen:Heur.Mint.Porcupine.Lu3@cqklclkig (B)
AviraTR/Spy.ClipBanker.bxblu
MicrosoftTrojan:MSIL/ClipBanker.GA!MTB
ArcabitTrojan.Mint.Porcupine.E8A02B
GDataGen:Heur.Mint.Porcupine.Lu3@cqklclkig
McAfeeArtemis!E290FB8A313E
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Clipper
PandaTrj/Genetic.gen
TrendMicro-HouseCallPUA.Win32.ProcHack.C
RisingTrojan.ClipBanker!8.5FB (CLOUD)
YandexTrojan.ClipBanker!WiUMw/zIf60
SentinelOneStatic AI – Malicious PE
FortinetMSIL/ClipBanker.PW!tr
AVGWin32:BankerX-gen [Trj]
Qihoo-360Win32/TrojanSpy.ClipBanker.HoMASOYA

How to remove MSIL/ClipBanker.PW?

MSIL/ClipBanker.PW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment