Trojan

TrojanBanker.MSIL.ClipBanker (file analysis)

Malware Removal

The TrojanBanker.MSIL.ClipBanker is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanBanker.MSIL.ClipBanker virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Anomalous binary characteristics

How to determine TrojanBanker.MSIL.ClipBanker?


File Info:

crc32: D0E07074
md5: 47bb2206c5406983ece71580296e7704
name: 47BB2206C5406983ECE71580296E7704.mlw
sha1: 244d641130e4af875153c0e2a1f67d818a9fdded
sha256: d25d9d1dad92948fd362febe973ef06a70bbdee3c0216650c7dc3b9b27c9cd35
sha512: e721ddd794fd919de1c0e17ae0d093acd1d883ec069c3642b45ff9c222de8ca9450715da0a11af2b84d3d4d21ddcc884f475b419515544df65dfea244c88e72c
ssdeep: 24576:mgFpbpFudQII2T5GgUWNEv+cf+BAttC5xKrfIrGCRMvVk3ea/:mgTbGdQII2ognEvl+0CPK8FRsk3n
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: FNaoDUhkfih0fIT
FileVersion: 3.7.9.2
CompanyName: Chat_Update
LegalTrademarks: sLTH
Comments: qavBgS4zaeiDjrv
ProductName: ExtraToolS
ProductVersion: 6.9.9.6
FileDescription: uYCJCA9eeuqcGSJ
OriginalFilename: BuildName.exe
Translation: 0x0409 0x04b0

TrojanBanker.MSIL.ClipBanker also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00568dbc1 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen10.44110
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Porcupine.cv3@cyaMgWaig
MalwarebytesTrojan.Clipper
ZillyaTrojan.ClipBanker.Win32.5764
SangforTrojan.MSIL.ClipBanker.GA
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojanBanker:MSIL/ClipBanker.42d0b77c
K7GWTrojan ( 00568dbc1 )
Cybereasonmalicious.6c5406
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ClipBanker.PW
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
BitDefenderGen:Heur.Mint.Porcupine.cv3@cyaMgWaig
NANO-AntivirusTrojan.Win32.ClipBanker.ibtcqs
MicroWorld-eScanGen:Heur.Mint.Porcupine.cv3@cyaMgWaig
TencentMsil.Trojan-banker.Clipbanker.Peqd
Ad-AwareGen:Heur.Mint.Porcupine.cv3@cyaMgWaig
SophosMal/Generic-S
ComodoMalware@#t6x4w3bi0o8n
BitDefenderThetaGen:NN.ZemsilF.34670.bm0@aqdLjFc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.ICLoader.tc
FireEyeGeneric.mg.47bb2206c5406983
EmsisoftGen:Heur.Mint.Porcupine.cv3@cyaMgWaig (B)
AviraTR/Spy.ClipBanker.qwktp
MicrosoftTrojan:MSIL/ClipBanker.GA!MTB
ArcabitTrojan.Mint.Porcupine.ED21ABB
AegisLabTrojan.MSIL.ClipBanker.7!c
GDataGen:Heur.Mint.Porcupine.cv3@cyaMgWaig
McAfeeArtemis!47BB2206C540
MAXmalware (ai score=81)
VBA32TrojanBanker.MSIL.ClipBanker
PandaTrj/Genetic.gen
RisingTrojan.ClipBanker!8.5FB (CLOUD)
YandexTrojan.ClipBanker!WiUMw/zIf60
SentinelOneStatic AI – Malicious PE
FortinetMSIL/ClipBanker.PW!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.ClipBanker.HoMASOcA

How to remove TrojanBanker.MSIL.ClipBanker?

TrojanBanker.MSIL.ClipBanker removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment