Spy Trojan

How to remove “TrojanSpy:MSIL/Hoetou.E”?

Malware Removal

The TrojanSpy:MSIL/Hoetou.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/Hoetou.E virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine TrojanSpy:MSIL/Hoetou.E?


File Info:

name: 049AF19DB6DDD998AC94.mlw
path: /opt/CAPEv2/storage/binaries/91df20cfd25c140da8728f67e004dc42277922aac62b8dce7589ee82f84ca52a
crc32: C740D6D1
md5: 049af19db6ddd998ac94be3147050217
sha1: c291c2a9d32bb5eff1c1bbdae3edf1df48a2cefe
sha256: 91df20cfd25c140da8728f67e004dc42277922aac62b8dce7589ee82f84ca52a
sha512: 52061f28ccdfde5afd77fe60565879d4ef1b3fad775573b8cb2974bea93ef2ce4e060ab795b70978250c38968a2603f721341c54f8b3e93e2515cf0c6842ddee
ssdeep: 3072:RFmUUScbaIuqgZD/XOuHG/NhHHHHHh4DnEEOKZHQE:DmUrGuHGjHHHHHhSEqHj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ACE39E123A97C312D81D6571C5EB012553E2ABC63673EA6ABC58235C5F02782BF42FAD
sha3_384: 07e986306151b29f1b6fd36a5c0e6f37b4e9780d1ad14e477a799bab42b708832b146233c294e5157a5b458d74723a81
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-06-12 06:03:35

Version Info:

Translation: 0x0000 0x04b0
Comments: HVMDfkMxVYsylIdPgleZ
CompanyName: fsAsnBjL Inc
FileDescription: fsAsnBjL
FileVersion: 4.2.7.1
InternalName: TyEfLBtt.exe
LegalCopyright: Copyright @ 2017
OriginalFilename: TyEfLBtt.exe
ProductName: fsAsnBjL
ProductVersion: 4.2.7.1
Assembly Version: 4.2.7.1

TrojanSpy:MSIL/Hoetou.E also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Agent.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tedy.22921
FireEyeGeneric.mg.049af19db6ddd998
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeePacked-MB!049AF19DB6DD
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004cd20d1 )
AlibabaTrojanSpy:MSIL/Hoetou.86958643
K7GWTrojan ( 004cd20d1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Multi.CND
CyrenW32/Trojan.FWT.gen!Eldorado
ESET-NOD32MSIL/Agent.ACU
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Nanocore-7788914-0
KasperskyHEUR:Backdoor.MSIL.Agent.gen
BitDefenderGen:Variant.Tedy.22921
NANO-AntivirusTrojan.Win32.Agent.epyagv
AvastWin32:DangerousSig [Trj]
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Variant.Tedy.22921
EmsisoftTrojan-Spy.Agent (A)
ComodoApplicUnwnt@#2gz6sltlemne5
DrWebTrojan.PWS.Multi.1693
ZillyaBackdoor.Agent.Win32.64043
TrendMicroBKDR_BLADABINDI.SMRQ
McAfee-GW-EditionPacked-MB!049AF19DB6DD
Trapminemalicious.high.ml.score
SophosMal/Generic-R + Troj/MSIL-JWJ
IkarusTrojan.MSIL.Inject
GDataGen:Variant.Tedy.22921
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Tedy.D5989
ViRobotTrojan.Win32.S.Agent.143850
ZoneAlarmHEUR:Backdoor.MSIL.Agent.gen
MicrosoftTrojanSpy:MSIL/Hoetou.E
CynetMalicious (score: 99)
AhnLab-V3PUP/Win32.Amonetize.C2016933
BitDefenderThetaGen:NN.ZemsilF.34742.iq1@aas!seh
ALYacGen:Variant.Tedy.22921
VBA32Backdoor.MSIL.Agent
MalwarebytesSpyware.Pony
TrendMicro-HouseCallBKDR_BLADABINDI.SMRQ
YandexTrojan.Agent!lK3A/7Grrh4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.ACU!tr
AVGWin32:DangerousSig [Trj]
Cybereasonmalicious.db6ddd
PandaTrj/CI.A

How to remove TrojanSpy:MSIL/Hoetou.E?

TrojanSpy:MSIL/Hoetou.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment