Spy Trojan

How to remove “Trojan:MSIL/SpySnake.MF!MTB”?

Malware Removal

The Trojan:MSIL/SpySnake.MF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/SpySnake.MF!MTB virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Binary compilation timestomping detected

How to determine Trojan:MSIL/SpySnake.MF!MTB?


File Info:

name: 49DA5C7E58F758439348.mlw
path: /opt/CAPEv2/storage/binaries/86ef306ecf41f569eda8ce9d60214b0b4750fc90ced0765dcd620cbd59cfd1de
crc32: AE4346A1
md5: 49da5c7e58f7584393484aa52977e189
sha1: d0352fa99fa2c322199d79e2ef0791f8ee52fffd
sha256: 86ef306ecf41f569eda8ce9d60214b0b4750fc90ced0765dcd620cbd59cfd1de
sha512: 7cf8d506bc7e379836c7d37005a6fd99aea37d2af7b58e48f050949577850cd80ff69744aaba94711caebea532170407a3c2a0e5c05701aca7fc3ce18f7ae9cb
ssdeep: 1536:NY5vCtM6egHE+oh4bgOo1yG6TTOU9peL7qQgyGAe:IvSegHE+mz7UG6TSU9gL7Gj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EC04F7437044E1DBD52E49F3B89FCAA152646DAF85909A6E33C8B76E40F3310025EFAD
sha3_384: 92662e96bfb71cbe817ba4891f233ac48b0cb5db3e232228fe149d5ab29f36a6ba844b2cbc108d65e777d4d004614d67
ep_bytes: ff250020400000000000000000000000
timestamp: 2098-02-27 01:31:05

Version Info:

Comments: 珜珦环珥珜环玲玻玳珜现珝珜珔珨
CompanyName: 珜珦环珥珜环玲玻玳珜现珝珜珔珨 Inc.
FileDescription: 珜珦环珥珜环玲玻玳珜现珝珜珔珨
FileVersion: 1.312.525.608
LegalCopyright: All Rights Reserved
InternalName: 珜珦环珥珜环玲玻玳珜现珝珜珔珨.exe
LegalTrademarks: 珜珦环珥珜环玲玻玳珜现珝珜珔珨
OriginalFilename: 珜珦环珥珜环玲玻玳珜现珝珜珔珨.exe
ProductName: 珜珦环珥珜环玲玻玳珜现珝珜珔珨
ProductVersion: 1.312.525.608
Assembly Version: 1.312.525.608
Translation: 0x0000 0x0514

Trojan:MSIL/SpySnake.MF!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.31197
FireEyeGeneric.mg.49da5c7e58f75843
McAfeeRDN/Generic Downloader.x
MalwarebytesTrojan.Downloader.MSIL.Generic
ZillyaDownloader.Agent.Win32.455207
SangforTrojan.Win32.Sabsik.FL
K7AntiVirusTrojan-Downloader ( 0058ac2a1 )
AlibabaTrojanSpy:MSIL/SpySnake.ef1b5ab2
K7GWTrojan-Downloader ( 0058ac2a1 )
Cybereasonmalicious.e58f75
CyrenW32/MSIL_Kryptik.EHH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.JNS
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderGen:Variant.MSILHeracles.31197
AvastWin32:Trojan-gen
TencentMsil.Trojan-downloader.Agent.Pgdm
Ad-AwareGen:Variant.MSILHeracles.31197
SophosMal/Generic-S
DrWebTrojan.DownLoader44.3921
TrendMicroTROJ_GEN.R03FC0GKQ21
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftGen:Variant.MSILHeracles.31197 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dldr.Agent.naflj
Antiy-AVLTrojan[Downloader]/MSIL.Agent
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:MSIL/SpySnake.MF!MTB
GDataGen:Variant.MSILHeracles.31197
CynetMalicious (score: 99)
AhnLab-V3Malware/Gen.Generic.C4796733
BitDefenderThetaGen:NN.ZemsilF.34084.lm0@a4ByrUdi
ALYacGen:Variant.MSILHeracles.31197
MAXmalware (ai score=85)
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallTROJ_GEN.R03FC0GKQ21
YandexTrojan.DL.Agent!tkbYdWV8pQg
IkarusTrojan-Downloader.MSIL.Discord
FortinetMSIL/Agent.JNS!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan:MSIL/SpySnake.MF!MTB?

Trojan:MSIL/SpySnake.MF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment