Trojan

Trojan:MSIL/Dnoper.EM!MTB removal instruction

Malware Removal

The Trojan:MSIL/Dnoper.EM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Dnoper.EM!MTB virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:MSIL/Dnoper.EM!MTB?


File Info:

name: 40B88D52DD272FD9D279.mlw
path: /opt/CAPEv2/storage/binaries/70206de0176a9ecc0c9a1e66ef25e746a73ec36b9e2a282fe5841b7df8b155ad
crc32: C0DC5F01
md5: 40b88d52dd272fd9d2799874bbed0675
sha1: e7f1ec527a0e4df500325320ddb73d953e584b79
sha256: 70206de0176a9ecc0c9a1e66ef25e746a73ec36b9e2a282fe5841b7df8b155ad
sha512: 2de44963b9dea1275c9dedb500e4c796599f08ee7d6923e6ff36c91bdd6a9b30725352f2bd14455ca159b685ce24f2a01f5b8ecd7753a5658c05fb2525cd1678
ssdeep: 24576:rQa+rRep38knZGbO4oFya8ZbRxaiXvnEc3Suvb7sNPwEFfTPCRi4Vz:rZ+rRe3zn4ioa8ZbRMiXO07sNPwERWV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11785AF07A5568E37C2667F7588EB091DC2E0D6727592EF0B362F18E1780A2319E172F7
sha3_384: 76a5774e70f43d66f2e93cf74a74a6367ec6c7de50665aa5134c5d542218e7b7839e081022820eea8360af94512cd6fa
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-09-07 23:40:57

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.2.7.1277
InternalName: SpotifyStartupTask
LegalCopyright: Copyright (c) 2023, Spotify Ltd
OriginalFilename: SpotifyStartupTask.exe
ProductName:
ProductVersion: 1.2.7.1277
Translation: 0x0000 0x04b0

Trojan:MSIL/Dnoper.EM!MTB also known as:

LionicTrojan.Win32.Dnoper.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.69633552
SkyhighBehavesLike.Win32.Generic.tc
McAfeeArtemis!40B88D52DD27
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005ac5cb1 )
K7AntiVirusTrojan ( 005ac5cb1 )
BitDefenderThetaGen:NN.ZemsilF.36792.Un1@aK2Oo6c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AJQX
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Uztuby-10009381-0
KasperskyHEUR:Trojan.MSIL.Dnoper.gen
BitDefenderTrojan.GenericKD.69633552
ViRobotTrojan.Win.Z.Agent.1810627
RisingTrojan.Dnoper!8.10CB3 (CLOUD)
SophosTroj/MSIL-TBT
F-SecureHeuristic.HEUR/AGEN.1323342
DrWebTrojan.Siggen21.28092
VIPRETrojan.GenericKD.69633552
TrendMicroTROJ_GEN.R011C0DK223
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.40b88d52dd272fd9
EmsisoftTrojan.GenericKD.69633552 (B)
IkarusTrojan.MSIL.Crypt
GDataTrojan.GenericKD.69633552
JiangminTrojan.MSIL.aosme
VaristW32/MSIL_Agent.FVY.gen!Eldorado
AviraHEUR/AGEN.1323342
Antiy-AVLTrojan/MSIL.Dnoper
Kingsoftmalware.kb.c.976
ArcabitTrojan.Generic.D4268610
ZoneAlarmHEUR:Trojan.MSIL.Dnoper.gen
MicrosoftTrojan:MSIL/Dnoper.EM!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5484342
VBA32TScope.Trojan.MSIL
MAXmalware (ai score=84)
DeepInstinctMALICIOUS
MalwarebytesBackdoor.DCRat
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R011C0DK223
TencentMsil.Trojan.Dnoper.Iqil
YandexTrojan.Kryptik!8iXUN+2uDaE
SentinelOneStatic AI – Malicious PE
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.27a0e4
AvastWin32:TrojanX-gen [Trj]

How to remove Trojan:MSIL/Dnoper.EM!MTB?

Trojan:MSIL/Dnoper.EM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment