Trojan

Trojan:MSIL/ClipBanker.G!MTB malicious file

Malware Removal

The Trojan:MSIL/ClipBanker.G!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/ClipBanker.G!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Trojan:MSIL/ClipBanker.G!MTB?


File Info:

name: 3221D9546893C7C01158.mlw
path: /opt/CAPEv2/storage/binaries/5a3d7b73c72baba732981fa1cb83b4f2d6d730f7ab35ed39e587363b2ca7dc4a
crc32: 25C34422
md5: 3221d9546893c7c01158550d1724b428
sha1: db5478fe48d9aca9179e49afe7d99d2782c154b8
sha256: 5a3d7b73c72baba732981fa1cb83b4f2d6d730f7ab35ed39e587363b2ca7dc4a
sha512: 24c9a6902c1e869a97498c0686bbac55c24b2b4094864bc7fc6013cd15466054b7707fd6d6ba194b401021e240082e86d0caad30240de73c6d69e609470e956a
ssdeep: 768:vwQXbxSjrEUHISyWbEcsWo5WK+ZQ0Mb0rv8/:vwQXbM3HIDtn+ZUb0rv8/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7C22A1877E48620C7FD5B760873A2110379FE46C513EB0E4AE0E4F91A7B2458B55FAB
sha3_384: 12169a058cf89c44031f75baeff75deca0fc45c4d9793af673088f58ec20d4dff4db91d64d787013b964b2aed404f7d1
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-05-14 15:39:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Host Process for Windows Services
InternalName: svchost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Microsoft Corporation.exe
ProductName: Microsoft® Windows® Operating System
Translation: 0x0000 0x04b0

Trojan:MSIL/ClipBanker.G!MTB also known as:

LionicWorm.MSIL.Gibus.o!c
MicroWorld-eScanGen:Heur.MSIL.Krypt.!cdmip!.2
ClamAVWin.Packed.Msilperseus-9885047-0
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeGenericRXML-IS!3221D9546893
MalwarebytesTrojan.FakeMS
ZillyaWorm.Gibus.Win32.14
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaWorm:MSIL/ClipBanker.7adac649
K7GWTrojan ( 700000121 )
Cybereasonmalicious.46893c
CyrenW32/MSIL_Troj.L.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.VY
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Worm.MSIL.Gibus.gen
BitDefenderGen:Heur.MSIL.Krypt.!cdmip!.2
NANO-AntivirusTrojan.Win32.Gibus.jvferz
AvastMSIL:Downloader-LX [Trj]
TencentMsil.Worm.Gibus.Fajl
EmsisoftGen:Heur.MSIL.Krypt.!cdmip!.2 (B)
F-SecureTrojan.TR/Dropper.Gen7
DrWebBackDoor.Bladabindi.1702
VIPREGen:Heur.MSIL.Krypt.!cdmip!.2
TrendMicroTROJ_GEN.R002C0DBP23
McAfee-GW-EditionGenericRXML-IS!3221D9546893
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.3221d9546893c7c0
SophosMal/ILAgent-A
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan.Bhat.A
JiangminWorm.MSIL.gdf
AviraTR/Dropper.Gen7
Antiy-AVLTrojan/MSIL.Agent
ArcabitTrojan.MSIL.Krypt.!cdmip!.2
ZoneAlarmHEUR:Worm.MSIL.Gibus.gen
MicrosoftTrojan:MSIL/ClipBanker.G!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Generic.C4228069
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.36196.bm0@ai2SWs
ALYacGen:Heur.MSIL.Krypt.!cdmip!.2
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DBP23
RisingWorm.Agent!8.25 (CLOUD)
IkarusTrojan.ILCrypt
MaxSecureTrojan.Malware.109060952.susgen
FortinetMSIL/Agent.YW!tr
AVGMSIL:Downloader-LX [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/ClipBanker.G!MTB?

Trojan:MSIL/ClipBanker.G!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment