Trojan

Trojan-Banker.MSIL.ClipBanker.bc information

Malware Removal

The Trojan-Banker.MSIL.ClipBanker.bc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.MSIL.ClipBanker.bc virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: replacespace.nss
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.MSIL.ClipBanker.bc?


File Info:

crc32: 97903D8E
md5: b5d3ecc7dcad884f41617453dc6cf11f
name: replacespace.nss
sha1: 8dbb6596db9f78d3e9ef508184ccaa9ec0f2a5c4
sha256: 16e23bac0529532ea9f85f2e00ab818af1c18adde01c0189bf76089ab2179bc5
sha512: a53afa194c1137dd4af8138fe0670196f68e16a5e4174e40e470869150495bce743ac445772ecb766d42c4731b3321cb8b332ecc36af1747a6e5bb4f6ddfd10b
ssdeep: 49152:M5gO+7IPjwyv+kIYyQ+RaeT7FpeipZYLbN8il5ya0UJmw:o3+8PMNkI1QVeTCWYL2K5ybUJm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Banker.MSIL.ClipBanker.bc also known as:

BkavW32.HfsAutoB.
FireEyeGeneric.mg.b5d3ecc7dcad884f
CylanceUnsafe
Invinceaheuristic
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallPAK_Crypt
GDataWin32.Trojan.Agent.SY0IVN
KasperskyTrojan-Banker.MSIL.ClipBanker.bc
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazrKYYjZsaG/QhxRcp0vQ1sR)
Endgamemalicious (high confidence)
F-SecureTrojan.TR/ClipBanker.roaty
TrendMicroPAK_Crypt
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.Themida
WebrootW32.Malware.Gen
AviraTR/ClipBanker.roaty
ZoneAlarmTrojan-Banker.MSIL.ClipBanker.bc
MicrosoftTrojan:Win32/Wacatac.D!ml
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
APEXMalicious
ESET-NOD32a variant of Win32/Packed.Themida.HFK
TencentMsil.Trojan-banker.Clipbanker.Phgd
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/ClipBanker.BC!tr
BitDefenderThetaGen:NN.ZexaF.34098.kB0aayIszBkO
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan-Banker.MSIL.ClipBanker.bc?

Trojan-Banker.MSIL.ClipBanker.bc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment