Spy Trojan

Trojan-Spy.MSIL.Spenoty removal tips

Malware Removal

The Trojan-Spy.MSIL.Spenoty is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.MSIL.Spenoty virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan-Spy.MSIL.Spenoty?


File Info:

name: DBC1A6FD82CF5EBAB80E.mlw
path: /opt/CAPEv2/storage/binaries/be802ef3fd9eea56af0b422f505da15d6c678261da5894fae9fe13171d93bc22
crc32: 639D8D59
md5: dbc1a6fd82cf5ebab80ecfb42b273a70
sha1: ed52eed9568de69422087044e0f085c68a95360e
sha256: be802ef3fd9eea56af0b422f505da15d6c678261da5894fae9fe13171d93bc22
sha512: 3d4cada7f82f786109f14f0658a55328b7bb5e3b44d2b9c6db9dec0ec5a79db87fb1369259237d229c25f69059b0e039aaaa074e582984315a91288b04354866
ssdeep: 12288:EHc6nc6CN50BK3sXdhq9oSxCP/9EZ3GgqM:Yc6nc6CN5gKkhq9o2CP1MGgqM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197154911A7911B49F13E57BA1020CA3917F9ACAAC362D74D3DECACDB7D65B8188C7213
sha3_384: c4089473bbcbd717bf414739e4936f52c620a02ed6bd92c50cf871c5137d1c3d7659faacf868eae12978709e5a77ab9c
ep_bytes: ff25002040008716993e8716993e8716
timestamp: 2094-09-05 16:15:01

Version Info:

Comments:
CompanyName:
FileDescription: HM-RAT
FileVersion: 2.0.0.0
InternalName: HM RAT -EviL HaLfmind.exe
LegalCopyright: Spy MAX © 2019
LegalTrademarks:
OriginalFilename: HM RAT -EviL HaLfmind.exe
ProductName: Spy MAX
ProductVersion: 2.0.0.0
Assembly Version: 2.0.0.0
Translation: 0x0000 0x04b0

Trojan-Spy.MSIL.Spenoty also known as:

LionicTrojan.MSIL.Spenoty.l!c
CAT-QuickHealTrojanSpy.MSIL
CylanceUnsafe
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H07A222
KasperskyHEUR:Trojan-Spy.MSIL.Spenoty.gen
AvastWin32:Malware-gen
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
JiangminTrojanSpy.MSIL.ccet
AviraHEUR/AGEN.1139272
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
McAfeeGenericRXRH-LY!DBC1A6FD82CF
VBA32Malware-Cryptor.MSIL.AgentTesla.Heur
APEXMalicious
AVGWin32:Malware-gen

How to remove Trojan-Spy.MSIL.Spenoty?

Trojan-Spy.MSIL.Spenoty removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment