Home Malware Programs Trojans TrojanSpy:MSIL/Omaneat

TrojanSpy:MSIL/Omaneat

Posted: October 26, 2015

Threat Metric

Threat Level: 8/10
Infected PCs: 7,204
First Seen: October 26, 2015
Last Seen: April 14, 2022
OS(es) Affected: Windows

TrojanSpy:MSIL/Omaneat is a cyber threat that may be propagated disguised as a software update, useful utility or software driver. However, these executable files may be propagated via shady and unreliable websites, so tech-savvy users may sense that there is something wrong with the download they are being offered. Unfortunately, PC users who don't pay attention to the stuff they download from the web may be exposed to files infected with TrojanSpy:MSIL/Omaneat easily and this may lead to very bad consequences.

TrojanSpy:MSIL/Omaneat is a high-level cyber threat that may cause all kinds of problems to the user whose computer is infected. As soon as the TrojanSpy:MSIL/Omaneat payload is downloaded, the threat may create an Autorun registry entry and drop its files to a hidden system folder. One of the file names often utilized by TrojanSpy:MSIL/Omaneat is 'system.exe,' but it is entirely possible that variations of TrojanSpy:MSIL/Omaneat may use other names too. Computers infected with TrojanSpy:MSIL/Omaneat may leak important data to cyber criminals. The Trojan may be used to exfiltrate login credentials, record keystrokes, spy on the user's activities, and even download and upload files to the targeted machine. While these features are quite basic, they are all cyber crooks may need to get access to your files and information, therefore threatening your privacy.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Qoobox\Quarantine\C\ProgramData\747400\helper.exe.vir File name: helper.exe.vir
Size: 647.68 KB (647680 bytes)
MD5: 02042d76cd8e6e6cff138c98f67015ed
Detection count: 190
Mime Type: unknown/vir
Path: C:\Qoobox\Quarantine\C\ProgramData\747400\helper.exe.vir
Group: Malware file
Last Updated: November 21, 2022
%ALLUSERSPROFILE%\895970\sysmon.exe File name: sysmon.exe
Size: 352.25 KB (352256 bytes)
MD5: f41d1dd11db45a295ca71b756e7cbffe
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\895970
Group: Malware file
Last Updated: January 21, 2017
file.exe File name: file.exe
Size: 655.36 KB (655360 bytes)
MD5: 7da7dce32928c4fc6490155c355aa95a
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 18, 2022
%ALLUSERSPROFILE%\337854\helper.exe File name: helper.exe
Size: 32.76 KB (32768 bytes)
MD5: 6f840b8bb2c3e253388579b9454ef1b3
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\337854
Group: Malware file
Last Updated: September 14, 2017
%ALLUSERSPROFILE%\Client\client.exe File name: client.exe
Size: 1.11 MB (1110016 bytes)
MD5: 5d0cc455b622a05ed4507e2dbac844d8
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Client
Group: Malware file
Last Updated: March 18, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\Client\client.exe%APPDATA%\clientmonitor.exe%WINDIR%\SysWOW64\winloguptades.exe
Loading...