Spy Trojan

What is “TrojanSpy:MSIL/Omaneat.C”?

Malware Removal

The TrojanSpy:MSIL/Omaneat.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/Omaneat.C virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanSpy:MSIL/Omaneat.C?


File Info:

crc32: 1FCA50C2
md5: fb9f758d7d969c109d07537c3f5c1f65
name: FB9F758D7D969C109D07537C3F5C1F65.mlw
sha1: 6e6cd7cf05377e23fa989c46b8b4080b5de86616
sha256: dc8467db9663fbd17542f93d1baed11365003cf64911b5c6ef837658cbb153ef
sha512: 184f20ad3564aa535ee8fb9779d6a2af7b90f97840e602fda5661c2fe2d1d76544f2d50186be26ec22f21464ccc3672832526d3cce1a2910bd3be9250f87e31a
ssdeep: 49152:htBJ7CNlqwO7p3DoWKcRR4pStEP80qr52pGfg3qri5u4+Ioj/+rYx:htT7CNlqwO7p3EVcR2N8trEQfd8vxoS
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: qJKNQTOg.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: qJKNQTOg.exe

TrojanSpy:MSIL/Omaneat.C also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILKrypt.55
FireEyeGeneric.mg.fb9f758d7d969c10
McAfeePacked-KL!FB9F758D7D96
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00508ccd1 )
BitDefenderGen:Variant.MSILKrypt.55
K7GWTrojan ( 00508ccd1 )
Cybereasonmalicious.d7d969
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-6331921-0
KasperskyBackdoor.Win32.Androm.muaq
AlibabaTrojan:Win32/Kryptik.ali2000016
NANO-AntivirusTrojan.Win32.Androm.emttlq
Ad-AwareGen:Variant.MSILKrypt.55
SophosMal/Generic-R + Troj/Kryptik-GW
ComodoMalware@#39hzw9m6q4rau
F-SecureTrojan.TR/Dropper.MSIL.Gen
DrWebTrojan.DownLoader24.10405
TrendMicroTROJ_GEN.R002C0PB221
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.MSILKrypt.55 (B)
IkarusTrojan.MSIL.Injector
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Androm
MicrosoftTrojanSpy:MSIL/Omaneat.C
ArcabitTrojan.MSILKrypt.55
AegisLabTrojan.Win32.Androm.m!c
ZoneAlarmBackdoor.Win32.Androm.muaq
GDataGen:Variant.MSILKrypt.55
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Siscos.C65127
BitDefenderThetaGen:NN.ZemsilF.34804.Rn0@a4l6XAo
ALYacGen:Variant.MSILKrypt.55
MalwarebytesMachineLearning/Anomalous.95%
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Injector.RVH
TrendMicro-HouseCallTROJ_GEN.R002C0PB221
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.YII!tr
AVGWin32:BotX-gen [Trj]
AvastWin32:BotX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Backdoor.Androm.HgIASOQA

How to remove TrojanSpy:MSIL/Omaneat.C?

TrojanSpy:MSIL/Omaneat.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment