Spy Trojan

TrojanSpy:MSIL/Omaneat.B removal tips

Malware Removal

The TrojanSpy:MSIL/Omaneat.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/Omaneat.B virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

How to determine TrojanSpy:MSIL/Omaneat.B?


File Info:

crc32: E5EE6648
md5: 17e7e94e7a53b9a8f6c1e5f8e352f075
name: 17E7E94E7A53B9A8F6C1E5F8E352F075.mlw
sha1: 3151b53c5fea7a0cadf2b0229c142a8258161215
sha256: 7d68bc913cfd23bf31db680253bd6c405982b6f365d8f4f46bf25575162c92b5
sha512: ca31d5e35ae6dbe8acecaa93c4eb1c114bae37306e750872c21291029569debf997a18bbea51e3631ad9c500b8cb4b22704b671645b2d62e7e2a2572a34a939b
ssdeep: 98304:YW5lUh7Wfs5cG0hDteW81vmSYM1lFlQxgptTlToXyIGaRTN7Ed6inK5On7VbXhn7:3lA7OG0hJeOSVLXa11Ed6mD7VbXd
type: PE32 executable (GUI) Intel 80386, for MS Windows, InnoSetup self-extracting archive

Version Info:

LegalCopyright: Copyright (C) 2020 Beam Development Limited
InternalName: Beam-Wallet
FileVersion: 5.2.10113.3424
CompanyName: Beam Development Limited
ProductName: Beam Wallet
ProductVersion: 5.2.10113.3424
FileDescription:
OriginalFileName:
Translation: 0x0409 0x04b0

TrojanSpy:MSIL/Omaneat.B also known as:

MicroWorld-eScanTrojan.GenericKD.45062854
FireEyeTrojan.GenericKD.45062854
Qihoo-360Win32/Trojan.bd1
ALYacTrojan.GenericKD.45062854
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.45062854
CyrenW32/Trojan.RSBZ-5673
SymantecRansom.Wannacry
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Convagent.gen
AlibabaTrojan:Win32/Convagent.08542668
Ad-AwareTrojan.GenericKD.45062854
EmsisoftTrojan.GenericKD.45062854 (B)
F-SecureTrojan.TR/AD.RMSRatKit.puqfd
McAfee-GW-EditionArtemis!Trojan
SophosGeneric PUA DB (PUA)
IkarusTrojan.Spy.Agent
AviraTR/AD.RMSRatKit.puqfd
MicrosoftTrojanSpy:MSIL/Omaneat.B
ArcabitTrojan.Generic.D2AF9AC6
ZoneAlarmHEUR:Trojan.Win32.Convagent.gen
GDataTrojan.GenericKD.45062854
CynetMalicious (score: 85)
McAfeeArtemis!17E7E94E7A53
MAXmalware (ai score=99)
VBA32Trojan.Convagent
MalwarebytesTrojan.Agent
PandaTrj/CI.A
ESET-NOD32a variant of Generik.HEZPVPE
TencentWin32.Trojan.Falsesign.Eaxr
eGambitPE.Heur.InvalidSig
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove TrojanSpy:MSIL/Omaneat.B?

TrojanSpy:MSIL/Omaneat.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment