Spy Trojan

Trojan:MSIL/Spynoon.AAUY!MTB removal instruction

Malware Removal

The Trojan:MSIL/Spynoon.AAUY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Spynoon.AAUY!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:MSIL/Spynoon.AAUY!MTB?


File Info:

name: 94D50D9FC6D05513554D.mlw
path: /opt/CAPEv2/storage/binaries/2f568d076a9ddef005b33f4effe71591a7b3f3dd9730f7e4c0456916db6eca90
crc32: 9C7B49FB
md5: 94d50d9fc6d05513554d332d198c556f
sha1: 8dd6ebeebc400d3e4ad91b06b8e8ff90fa66b561
sha256: 2f568d076a9ddef005b33f4effe71591a7b3f3dd9730f7e4c0456916db6eca90
sha512: 98924946deeba0e44e755ac8a43741d0424acdf7a3c3492acdea18b4f8e54097dda5eb3857a2099186f3bd7c37ac9886f317b5bf5c11a306db64fe48695eb138
ssdeep: 12288:OOWLL3AcHcptDToEVNLnJ3Jp9N9hn1W7tiZrym5cUOgn6aNuPDTwZaQ:O5LL8pZoel3fH9h1CtiZn16aAPDTw0Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BFF4010937BAAB23E47A47F905B1604847F064BE78BCD75A4CD2A4CB1AB7F001A51F1B
sha3_384: a25311d15a6862fa68f779bc2905286b10e9444781d737ed63b9a213242f712a82325636845fdbc01d1ae1375339921d
ep_bytes: ff250020400000000000000000000000
timestamp: 2073-12-20 16:04:30

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: TTNhom
FileVersion: 1.0.0.0
InternalName: Totag.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: Totag.exe
ProductName: TTNhom
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/Spynoon.AAUY!MTB also known as:

LionicTrojan.Win32.Noon.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.70252113
SkyhighBehavesLike.Win32.Generic.bc
McAfeeRDN/Generic PWS.y
MalwarebytesTrojan.MalPack.PNG.Generic
VIPRETrojan.GenericKD.70252113
SangforSpyware.Msil.Kryptik.Vgcc
K7AntiVirusTrojan ( 005a74e81 )
BitDefenderTrojan.GenericKD.70252113
K7GWTrojan ( 005a74e81 )
VirITTrojan.Win32.MSIL_Heur.A
SymantecScr.Malcode!gdn33
ESET-NOD32a variant of MSIL/Kryptik.AKAX
APEXMalicious
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
AlibabaTrojanSpy:MSIL/Spynoon.70497689
NANO-AntivirusTrojan.Win32.Noon.kdglvs
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:WcTCni8Kf+nm7Nq9HD99Vg)
SophosTroj/Krypt-ABH
F-SecureTrojan.TR/Kryptik.pjxss
DrWebTrojan.Packed2.45882
Trapminesuspicious.low.ml.score
FireEyeTrojan.GenericKD.70252113
EmsisoftTrojan.GenericKD.70252113 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Kryptik.pjxss
VaristW32/MSIL_Agent.GVD.gen!Eldorado
MicrosoftTrojan:MSIL/Spynoon.AAUY!MTB
XcitiumMalware@#7n4q17w8rxxj
ArcabitTrojan.Generic.D42FF651
ZoneAlarmHEUR:Trojan-Spy.MSIL.Noon.gen
GDataTrojan.GenericKD.70252113
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.TrojanX-gen.C5538600
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.70252113
MAXmalware (ai score=81)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.F0D1C00K623
TencentMalware.Win32.Gencirc.13f49b75
IkarusTrojan-Spy.FormBook
MaxSecureTrojan.Malware.74501276.susgen
FortinetMSIL/GenKryptik.GLXZ!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/Spynoon.AAUY!MTB?

Trojan:MSIL/Spynoon.AAUY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment