Spy Trojan

Trojan:Win32/SpyNoon.BSA!MTB removal

Malware Removal

The Trojan:Win32/SpyNoon.BSA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SpyNoon.BSA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/SpyNoon.BSA!MTB?


File Info:

name: 902F81E7CC00C963ACC1.mlw
path: /opt/CAPEv2/storage/binaries/616838e6dfff493e546f51436ee3c0bbe99d459c18abbbb71a6207555e9d73e6
crc32: B1044BF9
md5: 902f81e7cc00c963acc14ab5d965358a
sha1: fee22df6132712432cb79519ebbc58d23a5ef8d3
sha256: 616838e6dfff493e546f51436ee3c0bbe99d459c18abbbb71a6207555e9d73e6
sha512: 86e2d763a2c8e02b2167e8b3b5b5fd31b29e237c70d082683503c3302ef08113288a73f5024732c94b88c7361008292c6ac80970591c5795d203bcff06664fb0
ssdeep: 6144:wBlL/cf5D6b+2XHjDQ8OgQG9bCxyFpZjvYsmmtsWh:CeBD6iEQ7g9PvGU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18754122B61E408FBED2303B269677F7AC2768A0C14A14783A7F02D7779631D6C95E253
sha3_384: 1eac87bdf2418255ea5303252f369d7d217e787cbc4e1bc1eea8a84c571757aabde22332f6c5b7a00acd8e30657711f6
ep_bytes: 81ec840100005355565733db68018000
timestamp: 2016-04-02 03:20:05

Version Info:

0: [No Data]

Trojan:Win32/SpyNoon.BSA!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zapchast.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.902f81e7cc00c963
CAT-QuickHealTrojan.Azorult
ALYacTrojan.Generic.31115828
CylanceUnsafe
VIPREWin32.Malware!Drop
SangforTrojan.Win32.Injector.EQKK
K7AntiVirusTrojan ( 005899681 )
AlibabaTrojan:Win32/SpyNoon.da79045d
K7GWTrojan ( 005899681 )
Cybereasonmalicious.7cc00c
VirITTrojan.Win32.PSWStealer.DCX
CyrenW32/Injector.AOJ.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Formbook.AA
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Zapchast.gen
BitDefenderTrojan.Generic.31115828
NANO-AntivirusTrojan.Win32.Zapchast.jibjzx
MicroWorld-eScanTrojan.Generic.31115828
AvastWin32:Trojan-gen
TencentWin32.Trojan.Zapchast.Hphv
Ad-AwareTrojan.Generic.31115828
EmsisoftTrojan.Generic.31115828 (B)
ComodoMalware@#380uans5d7ybk
DrWebTrojan.Packed2.43584
TrendMicroTrojanSpy.Win32.NOON.UHBAZCLQK
McAfee-GW-EditionRDN/Formbook
SophosMal/Generic-R + Troj/Formbo-BKP
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Stealer.FormBook.SRF84H
JiangminTrojan.Zapchast.tb
WebrootW32.Trojan.NSISX.Spy.Gen
AviraTR/Injector.jfvop
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.34D5641
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D1DACA34
ZoneAlarmHEUR:Trojan.Win32.Zapchast.gen
MicrosoftTrojan:Win32/SpyNoon.BSA!MTB
AhnLab-V3Trojan/Win.Frs.C4737936
McAfeeRDN/Formbook
VBA32Trojan.Injector
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTrojanSpy.Win32.NOON.UHBAZCLQK
YandexTrojan.Zapchast!ExiDAWVITmA
IkarusTrojan.NSIS.Agent.S
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Injector.358A!tr
AVGWin32:Trojan-gen
PandaTrj/WLT.G

How to remove Trojan:Win32/SpyNoon.BSA!MTB?

Trojan:Win32/SpyNoon.BSA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment