Spy Trojan

How to remove “Trojan:MSIL/SpySnake.MJ!MTB”?

Malware Removal

The Trojan:MSIL/SpySnake.MJ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/SpySnake.MJ!MTB virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Trojan:MSIL/SpySnake.MJ!MTB?


File Info:

name: D1E3FD66AD9D3F486ADA.mlw
path: /opt/CAPEv2/storage/binaries/8e4ca12811ae20874923d590e85c6e0a4c591fa3dfe754cce7c47433b713b9c8
crc32: B6525482
md5: d1e3fd66ad9d3f486ada819177faa8c6
sha1: 59cece6df8422b80b4a8e93199584fb73ab36f23
sha256: 8e4ca12811ae20874923d590e85c6e0a4c591fa3dfe754cce7c47433b713b9c8
sha512: e83987e3af799aa32ca8368da86707699c3a41ec781f85292d7e410f92ef407d7f049a47d87ad645de21d1efb828dee42bd260b35e0f9ae95d84462f84e1905f
ssdeep: 1536:9Nf77B7bFH7XcksAY7ooovoycKyKyKyKyKyKy9uC7CvvvvvvlOUSTNmlOC:9Nf77BeklYh111111mOUjd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B10476E872D1E279F811CF3D1A207C7177B509ABCC719D19A9ACEEF0C520EAE1B21945
sha3_384: 39382e2fc533a24fc38fdf62cef2d8a7ae2dfee7509b85dc489480b3bd26bb149b317ffc96891b7c9cabe6449b791796
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-21 00:01:56

Version Info:

Translation: 0x0000 0x04b0
Comments: OpenVPN Daemon
CompanyName: The OpenVPN Project
FileDescription: OpenVPN Daemon
FileVersion: 2.5.0.0
InternalName: 333dnzn.exe
LegalCopyright: Copyright © The OpenVPN Project
LegalTrademarks:
OriginalFilename: 333dnzn.exe
ProductName: OpenVPN
ProductVersion: 2.5.0.0
Assembly Version: 2.5.0.0

Trojan:MSIL/SpySnake.MJ!MTB also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.1167
MicroWorld-eScanTrojan.GenericKD.48070301
FireEyeGeneric.mg.d1e3fd66ad9d3f48
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
ZillyaDownloader.Agent.Win32.460205
SangforTrojan.MSIL.Noon.gen
K7AntiVirusTrojan-Downloader ( 0058d47a1 )
AlibabaTrojan:MSIL/Generic.220a960d
K7GWTrojan-Downloader ( 0058d47a1 )
Cybereasonmalicious.df8422
BitDefenderThetaGen:NN.ZemsilCO.34182.lm0@aaS8AJb
SymantecTrojan Horse
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.KCC
TrendMicro-HouseCallTrojan.MSIL.SABSIK.USMANAL22
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderTrojan.GenericKD.48070301
ViRobotTrojan.Win32.Z.Agent.183296.YL
AvastWin32:DropperX-gen [Drp]
TencentMsil.Trojan-downloader.Agent.Wrzv
EmsisoftTrojan.GenericKD.48070301 (B)
ComodoMalware@#jeu798ctecwm
TrendMicroTrojan.MSIL.SABSIK.USMANAL22
McAfee-GW-EditionRDN/Generic Downloader.x
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
AviraTR/Dropper.MSIL.mbmzk
MAXmalware (ai score=80)
Antiy-AVLTrojan[Spy]/MSIL.Noon
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:MSIL/SpySnake.MJ!MTB
GDataTrojan.GenericKD.48070301
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4926280
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.3975110196
APEXMalicious
RisingMalware.Obfus/MSIL@AI.90 (RDM.MSIL:NB9sJsyV80bDZO4WesFEEQ)
YandexTrojan.DL.Agent!D9boS93njsc
IkarusTrojan-Downloader.MSIL.Agent
MaxSecureTrojan.Malware.73691310.susgen
FortinetMSIL/Agent.KCC!tr.dldr
WebrootW32.Trojan.Gen
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/SpySnake.MJ!MTB?

Trojan:MSIL/SpySnake.MJ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment