Trojan

About “Trojan:MSIL/Snovir.psyA!MTB” infection

Malware Removal

The Trojan:MSIL/Snovir.psyA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Snovir.psyA!MTB virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan:MSIL/Snovir.psyA!MTB?


File Info:

name: C17646FDCAE0D65CF367.mlw
path: /opt/CAPEv2/storage/binaries/db2f8c5c0714a7b5e5b8de837af1296d9a895165da4db7055cfe7840677f2436
crc32: DECC00E2
md5: c17646fdcae0d65cf367327e4c58b6d5
sha1: ec01d67528f27aac4fcdfe0f718e9c56d553e0d6
sha256: db2f8c5c0714a7b5e5b8de837af1296d9a895165da4db7055cfe7840677f2436
sha512: 1d1403c143e154172e7f8b88b1f285ba62eeca0278a35536880a4d17b766400c075347e5c551dd2a8038a727075e01fb4e945daf883ae07c72e05a739a11a875
ssdeep: 384:YTTmu4hpSAeO4UB0v67VV0KOjlJAn7f78HYmlMzupKb1Zg3BvSNZ0AL2QjpZyBH4:Ya4AeO4U2v6KhvwTL2YpIBHAKRP8
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D8E2190922CCC6B5F9AC8E7C28F5452803F5D65B7512EB97CDC1A0D82F36BD64609AE3
sha3_384: fdeb7ebe133b6bcfd01318aa43b6e0504b18bb7d68131c76d8eb61a88114a9c542dc0e20a4eda397bb32fc83e65c6759
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-11-07 03:36:54

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: credentials.exe
LegalCopyright:
OriginalFilename: credentials.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan:MSIL/Snovir.psyA!MTB also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Keylogger.i!c
CynetMalicious (score: 99)
SkyhighGenericRXUJ-TP!C17646FDCAE0
McAfeeGenericRXUJ-TP!C17646FDCAE0
Cylanceunsafe
VIPREGen:Variant.Cerbu.153559
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 004bcf421 )
AlibabaTrojanPSW:MSIL/Snovir.f9d53b17
K7GWSpyware ( 004bcf421 )
ArcabitTrojan.Cerbu.D257D7
VirITTrojan.Win32.GenusT.EFUK
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Spy.Keylogger.AVQ
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefenderGen:Variant.Cerbu.153559
MicroWorld-eScanGen:Variant.Cerbu.153559
AvastWin32:SpywareX-gen [Trj]
TencentTrojan-Psw.Msil.Stealer.k
EmsisoftGen:Variant.Cerbu.153559 (B)
F-SecureHeuristic.HEUR/AGEN.1305397
DrWebTrojan.PWS.StealerNET.145
ZillyaTrojan.Keylogger.Win32.76433
TrendMicroTROJ_GEN.R002C0DA924
SophosTroj/Steal-CZT
IkarusTrojan-Spy.MSIL.Agent
VaristW32/Trojan.IQI.gen!Eldorado
AviraHEUR/AGEN.1305397
Antiy-AVLTrojan[Spy]/MSIL.KeyLogger
MicrosoftTrojan:MSIL/Snovir.psyA!MTB
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stealer.gen
GDataGen:Variant.Cerbu.153559
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5263256
ALYacTrojan.MSIL.Stealer.gen
TACHYONTrojan-PWS/W32.DN-InfoStealer.31744.B
VBA32Trojan.MSIL.InfoStealer.gen.D
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AC
TrendMicro-HouseCallTROJ_GEN.R002C0DA924
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Keylogger.AVQ!tr.spy
AVGWin32:SpywareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/Snovir.psyA!MTB?

Trojan:MSIL/Snovir.psyA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment