Spy Trojan

Trojan-Spy.MSIL.Stealer.bno removal guide

Malware Removal

The Trojan-Spy.MSIL.Stealer.bno is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.MSIL.Stealer.bno virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Spy.MSIL.Stealer.bno?


File Info:

crc32: 157F6569
md5: c3482ddd1261f2c96f49265c9e6a9908
name: C3482DDD1261F2C96F49265C9E6A9908.mlw
sha1: 3a2563046e02486aa4b021aef6c1dd2461dcee53
sha256: f871c7238a02fb54ed056c1ff6e930ae4a613f8a1555ae78e4e9434ab498a7b2
sha512: bf995c7b2d24474b3af69142dead0154d1f5691ff1957f36433d7c9f385e51511af2ca7324b30c75b72bd0647bcbd7e650c141787da0ab73cb58e967961813e8
ssdeep: 49152:csfzfWIal+SodHmXU6EXdhb6531/T/atehpCh/bz:ZzWJl+Xgd1/T/atupCBbz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2020 sc, Inc.
InternalName: vmnetgau
FileVersion: 16.1.0 build-17198959
CompanyName:
ProductName:
ProductVersion: 16.1.0 build-17198959
FileDescription:
OriginalFilename: vmnetgau.exe
Translation: 0x0409 0x04b0

Trojan-Spy.MSIL.Stealer.bno also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen13.59660
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/SpyNoon.1e49955f
K7GWTrojan ( 004beeaf1 )
Cybereasonmalicious.46e024
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.J suspicious
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastFileRepMalware
ClamAVWin.Malware.Bladabindi-9785195-0
KasperskyTrojan-Spy.MSIL.Stealer.bno
BitDefenderTrojan.GenericKD.37123243
MicroWorld-eScanTrojan.GenericKD.37123243
Ad-AwareTrojan.GenericKD.37123243
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34758.UD0@aO@hgFei
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.c3482ddd1261f2c9
EmsisoftTrojan.GenericKD.37123243 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASBOL.C669
MicrosoftTrojan:MSIL/SpyNoon.RTU!MTB
AegisLabTrojan.Win32.Malicious.4!c
GDataWin32.Trojan.Schtasks.ABZK2I
Acronissuspicious
McAfeeArtemis!C3482DDD1261
MAXmalware (ai score=81)
VBA32Trojan.Zpevdo
MalwarebytesSpyware.Agent
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BH01FJ21
RisingPUF.Pack-Enigma!1.BA33 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan-Spy.MSIL.Stealer.bno?

Trojan-Spy.MSIL.Stealer.bno removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment