Spy Trojan

About “Trojan:MSIL/SpyNoon.AMBF!MTB” infection

Malware Removal

The Trojan:MSIL/SpyNoon.AMBF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/SpyNoon.AMBF!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:MSIL/SpyNoon.AMBF!MTB?


File Info:

name: 462462854C9C314D48CC.mlw
path: /opt/CAPEv2/storage/binaries/aeb352e06454b7654c8698beb1db840631d4d4d1a2e1cace5df68814a0906888
crc32: 6E06095B
md5: 462462854c9c314d48cc16c0634ed018
sha1: 5028a9968c88de9b8376683a61ec2c2635f9e6ee
sha256: aeb352e06454b7654c8698beb1db840631d4d4d1a2e1cace5df68814a0906888
sha512: 24a62bcb8a9b3ab79548f39cda886a4acdb1ee5ad480a103e8fe236916b18ed2b65c7c10dbb70e514f3bb13be093456a1c186a6fbbcf22ea9078ba2a3a90c920
ssdeep: 12288:TKi8momWOHSPIr45GFvd1a84SRZ3+K82vtv98:6b/BQqWVA84m+K82vr8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T141C4E007B58D831EDD6806B93435023083B8AF1B5912EAC6BCCAFCBF09B5B5D56056DB
sha3_384: 2dcc243ddca0659949bdd0ae286e77cbb52f07bb4f71c22b3eb88747c54b3bf7f710c39983ea28fe0523901d796069c7
ep_bytes: ff250020400042353843353935483535
timestamp: 2023-12-22 00:58:56

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Calculadorab Matrizes
FileVersion: 5.7.0.0
InternalName: Xvqe.exe
LegalCopyright: 2024
LegalTrademarks:
OriginalFilename: Xvqe.exe
ProductName: Calculadora Matrizes
ProductVersion: 5.7.0.0
Assembly Version: 7.0.0.0

Trojan:MSIL/SpyNoon.AMBF!MTB also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Agensla.i!c
Elasticmalicious (high confidence)
FireEyeIL:Trojan.MSILZilla.43935
SkyhighBehavesLike.Win32.Generic.hc
McAfeeArtemis!462462854C9C
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.MSIL_Heur.A
SymantecScr.Malcode!gdn33
ESET-NOD32a variant of MSIL/Kryptik.AKKX
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderIL:Trojan.MSILZilla.43935
MicroWorld-eScanIL:Trojan.MSILZilla.43935
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.13fabeec
EmsisoftIL:Trojan.MSILZilla.43935 (B)
DrWebTrojan.DownLoaderNET.710
VIPREIL:Trojan.MSILZilla.43935
SophosTroj/Krypt-ABH
IkarusTrojan.MSIL.Crypt
GoogleDetected
Kingsoftmalware.kb.c.972
MicrosoftTrojan:MSIL/SpyNoon.AMBF!MTB
ArcabitIL:Trojan.MSILZilla.DAB9F
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataIL:Trojan.MSILZilla.43935
VaristW32/MSIL_Agent.HCU.gen!Eldorado
AhnLab-V3Malware/Win.Generic.C5566038
ALYacIL:Trojan.MSILZilla.43935
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.MSIL.Generic
PandaTrj/GdSda.A
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:vtDDHheI4nOlfRmh4uNCbQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.GOTT!tr
BitDefenderThetaGen:NN.ZemsilF.36802.Jm0@aKdyh6l
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.54c9c3
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/SpyNoon.AMBF!MTB?

Trojan:MSIL/SpyNoon.AMBF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment