Spy Trojan

TrojanSpy:MSIL/VB.M removal tips

Malware Removal

The TrojanSpy:MSIL/VB.M is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/VB.M virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine TrojanSpy:MSIL/VB.M?


File Info:

name: D65F5A594AA97B708C58.mlw
path: /opt/CAPEv2/storage/binaries/1145c82ae33ff22f62ea59f20b3845b2b9d5ad904515db81a64e6f6afa7f034a
crc32: A10D86D4
md5: d65f5a594aa97b708c585b0c0f62c7b5
sha1: 793ed8092b3f4bb0a7ccb1260a9c711b5598da7c
sha256: 1145c82ae33ff22f62ea59f20b3845b2b9d5ad904515db81a64e6f6afa7f034a
sha512: e2e85764a2e801e7d76d983a04c81a82f6741f1a870923e5d0a6a331e0945d3d48ac775ace7e56375c327e76c42319427eb94576c4df2c5cc315efbcc5348f80
ssdeep: 12288:xLo2WjSRNHOt2wkMkHknk8hJ9G0zQgDQ1XW:YyU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144A43C653A90D62AD4544C78FA73B1C417F69DB3EA42CA00EDFB356A8F30A229F4D117
sha3_384: 2080ab543cac50be29d07538b93f3bed0dfe30cf6de9a8e22b55212e79841bbd7d4e8e58b2780e65dcd3917116b693fd
ep_bytes: ff250020400000000000000000000000
timestamp: 2010-03-02 07:52:04

Version Info:

Translation: 0x0000 0x04b0
Comments: 541's Stub for Keylogger
CompanyName: 541
FileDescription: 541's Stub
FileVersion: 9.0.0.20
InternalName: Stub.exe
LegalCopyright: Copyright © 541
OriginalFilename: Stub.exe
ProductName: 541's Stub
ProductVersion: 9.0.0.20
Assembly Version: 2.0.0.2

TrojanSpy:MSIL/VB.M also known as:

LionicTrojan.Win32.Genome.4!c
MicroWorld-eScanGen:Heur.MSIL.Krypt.1
ClamAVWin.Trojan.Agent-406657
FireEyeGeneric.mg.d65f5a594aa97b70
ALYacGen:Heur.MSIL.Krypt.1
Cylanceunsafe
ZillyaBackdoor.PePatch.Win32.36738
SangforTrojan.MSIL.Crypt.atAH
K7AntiVirusTrojan ( 0020141a1 )
AlibabaTrojanSpy:MSIL/Qhost.6d993ba0
K7GWTrojan ( 0020141a1 )
Cybereasonmalicious.94aa97
BitDefenderThetaGen:NN.ZemsilF.36250.Cm1@a8QHcdm
VirITTrojan.Win32.Generic.VRZ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32MSIL/Qhost.O
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.MSIL.Krypt.1
NANO-AntivirusTrojan.Win32.Qhost.dcnbzv
SUPERAntiSpywareTrojan.Agent/Gen-Keypass
AvastMSIL:Crypt-AH [Drp]
RisingDropper.Generic!8.35E (CLOUD)
TACHYONTrojan/W32.DN-Genome.467500
EmsisoftGen:Heur.MSIL.Krypt.1 (B)
BaiduMSIL.Trojan.Qhost.b
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.AVKill.11615
VIPREGen:Heur.MSIL.Krypt.1
McAfee-GW-EditionGenericRXHQ-GD!D65F5A594AA9
SophosMal/EncPk-RX
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.MSIL.Krypt.1
JiangminTrojan.Generic.dwmwo
WebrootSystem.Monitor.Keylogger.Gen
AviraTR/Spy.Gen
Antiy-AVLTrojan[Spy]/MSIL.KeyLogger
XcitiumMalware@#3k0n7u4g1pyw7
ArcabitTrojan.MSIL.Krypt.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanSpy:MSIL/VB.M
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Generic.R337884
Acronissuspicious
McAfeeGenericRXHQ-GD!D65F5A594AA9
MAXmalware (ai score=100)
VBA32Trojan.MSIL.Buts.gen
MalwarebytesMalware.AI.4124478404
PandaGeneric Malware
TencentMalware.Win32.Gencirc.115a4f73
YandexTrojan.Agent!ODcQskcpS48
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/AntiAV.NET!tr
AVGMSIL:Crypt-AH [Drp]
DeepInstinctMALICIOUS

How to remove TrojanSpy:MSIL/VB.M?

TrojanSpy:MSIL/VB.M removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment