Spy Trojan

Trojan:Win32/SpyEyes.RMA!MTB removal instruction

Malware Removal

The Trojan:Win32/SpyEyes.RMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SpyEyes.RMA!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/SpyEyes.RMA!MTB?


File Info:

name: 1813923591B762868F22.mlw
path: /opt/CAPEv2/storage/binaries/9392080b122c7d0c93c89e76affce2da6cd3ead6639ebe6d20468e0545938009
crc32: 45A33D6B
md5: 1813923591b762868f22bd56b103d67f
sha1: faf7d964a568f7fb823cc3112c3b38cc40217203
sha256: 9392080b122c7d0c93c89e76affce2da6cd3ead6639ebe6d20468e0545938009
sha512: 1703ed356422cfe02517ec60612443fb864170162c375d2ffe6cb31757afb2cd08df503e0648d70784d32452753e67a718cb8e2a790fb284e1276807b6a540e4
ssdeep: 49152:6DpYqWCUnGfIElMgdjm70QYHnXZTEncoEW0sbN+0yM0AZBm/:6DpYqWCUnGfIElMgdjm70QYHnXZTEncX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11895BF2FE5ADB042CC2294F5ADD992A2D82FC21107AB4D5333FD1D09C64982FBB1676D
sha3_384: 38c44cf76c655ccfbc7b6c871d37e1318cb7d2611572f19245c13d7e5534baa37561c9e86f4493d9b3dfc7311458568f
ep_bytes: e88b040000e98efeffff3b0d74704000
timestamp: 2021-11-22 08:33:43

Version Info:

CompanyName: TODO:
FileDescription: Help
FileVersion: 1.0.0.1
InternalName: Help
LegalCopyright: TODO: (c) . All rights reserved.
OriginalFilename: Help
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04b0

Trojan:Win32/SpyEyes.RMA!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Trickster.7!c
Elasticmalicious (high confidence)
DrWebTrojan.KillProc2.17021
MicroWorld-eScanTrojan.GenericKD.38093251
FireEyeTrojan.GenericKD.38093251
ALYacTrojan.GenericKD.38093251
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3628720
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanBanker:Win32/SpyEyes.9a762252
K7GWTrojan ( 0058ac2f1 )
K7AntiVirusTrojan ( 0058ac2f1 )
CyrenW32/Trickster.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNKX
TrendMicro-HouseCallTROJ_GEN.R002C0DKP21
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Banker.Win32.Trickster.gen
BitDefenderTrojan.GenericKD.38093251
AvastWin32:BankerX-gen [Trj]
Ad-AwareTrojan.GenericKD.38093251
SophosML/PE-A
TrendMicroTROJ_GEN.R002C0DKP21
McAfee-GW-EditionBehavesLike.Win32.Suspect.tt
EmsisoftTrojan.GenericKD.38093251 (B)
GDataWin32.Trojan.PSE.1PYRF83
JiangminTrojan.Trickpak.mi
AviraTR/Kryptik.cjwcd
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.34D65D3
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Kryptik.1981440.BO
MicrosoftTrojan:Win32/SpyEyes.RMA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R452340
McAfeeGenericRXQW-AO!1813923591B7
VBA32TrojanBanker.Win64.Convagent
MalwarebytesTrojan.TrickBot
APEXMalicious
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.GenKryptik!TUvqGoGa4nc
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_100%
FortinetW32/AGen.HY!tr
AVGWin32:BankerX-gen [Trj]
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/SpyEyes.RMA!MTB?

Trojan:Win32/SpyEyes.RMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment