Trojan

Trojan:MSIL/SnakeKeylogger.DS!MTB (file analysis)

Malware Removal

The Trojan:MSIL/SnakeKeylogger.DS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/SnakeKeylogger.DS!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/SnakeKeylogger.DS!MTB?


File Info:

crc32: A5660097
md5: f28a8b7fc8c60cb1327b4983a5bf7816
name: F28A8B7FC8C60CB1327B4983A5BF7816.mlw
sha1: ff32ef5aca0a1005ad1871205bf33a1b4a9a6fbd
sha256: 21f9efa2dc23445571bc45df18b359a12282e44af4f33fcdb5b2ced6df8b9db5
sha512: d240e93296aa32091bd7e15fc4b7c58a8296c1f169dcbe2123fe10ba1f041ac19a14a898ce24417f654c11315fd8226a8cc2f5239094d5be309d9ee9bbe4ab34
ssdeep: 24576:g/Vq04F2xa0yetrA9XFfCRtCtqTbVzPNC+ydQDhgCDCwYXX0YNIc/IFP898uEwN:6w2LrqVC2tebVzVC+ydQdgCDKUE393N
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 2012 xdpirate
Assembly Version: 1.7.1.2
InternalName: SiteIdentityPermissionAttribu.exe
FileVersion: 1.7.1.2
CompanyName: xdpirate
LegalTrademarks:
Comments: GameLauncher
ProductName: GameLauncher
ProductVersion: 1.7.1.2
FileDescription: Game Launcher
OriginalFilename: SiteIdentityPermissionAttribu.exe

Trojan:MSIL/SnakeKeylogger.DS!MTB also known as:

K7AntiVirusTrojan ( 0053ba121 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.964
CynetMalicious (score: 99)
CAT-QuickHealBackdoor.MSIL
ALYacTrojan.GenericKD.37310033
CylanceUnsafe
SangforBackdoor.MSIL.Remcos.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/SnakeKeylogger.d56c5fd0
K7GWTrojan ( 0053ba121 )
CyrenW32/MSIL_Troj.BGW.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Rescoms.B
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Agent-9882319-0
KasperskyHEUR:Backdoor.MSIL.Remcos.gen
BitDefenderTrojan.GenericKD.37310033
NANO-AntivirusTrojan.Win32.Remcos.ixwavg
MicroWorld-eScanTrojan.GenericKD.37310033
Ad-AwareTrojan.GenericKD.37310033
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34058.Bn0@a8Ja2nl
TrendMicroBackdoor.MSIL.REMCOS.USMANGT21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.f28a8b7fc8c60cb1
EmsisoftTrojan.Crypt (A)
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1105296
MicrosoftTrojan:MSIL/SnakeKeylogger.DS!MTB
GridinsoftTrojan.Win32.Kryptik.dd!n
GDataTrojan.GenericKD.37310033
McAfeeArtemis!F28A8B7FC8C6
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.AveMaria
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.MSIL.REMCOS.USMANGT21
IkarusTrojan.Inject
FortinetMalicious_Behavior.SB
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Remcos.HgIASZUA

How to remove Trojan:MSIL/SnakeKeylogger.DS!MTB?

Trojan:MSIL/SnakeKeylogger.DS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment