Spy Trojan

Trojan:Win32/Spynoon.MXA!MTB (file analysis)

Malware Removal

The Trojan:Win32/Spynoon.MXA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Spynoon.MXA!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Anomalous binary characteristics

How to determine Trojan:Win32/Spynoon.MXA!MTB?


File Info:

crc32: 40E016E0
md5: ba55a21782837250fcdedc578175c874
name: BA55A21782837250FCDEDC578175C874.mlw
sha1: 539a65f405acb7d5a1ba4fb3ee7dd0fa75bab33d
sha256: 1925c407d4f24ed0e1e002a57042e4cec58f9e09bde7c441f6f5b9ca5748ea20
sha512: e516db3a0459246c7fb03347e348541276f886eb44b77a28626491f4291d9840963d564a38ecb009ce74c06f5103b4d825701050e0770d19d7964ed3698b2147
ssdeep: 3072:6eYBCwqDxkJkMNum9vpXy156lWydd48NwFIhLbJnNO7MwIBYLrhjawzYj26f5JZ:6DIfIX9vJy12Td5NJncIw9pjaK6f5JZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Spynoon.MXA!MTB also known as:

K7AntiVirusTrojan ( 0057a51b1 )
CynetMalicious (score: 99)
ALYacTrojan.Downloader.NSIS.GJ
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 0057a51b1 )
Cybereasonmalicious.405acb
CyrenW32/Injector.AGV.gen!Eldorado
SymantecTrojan.Dropper
ESET-NOD32a variant of Win32/Injector.EPBA
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
BitDefenderTrojan.Downloader.NSIS.GJ
MicroWorld-eScanTrojan.Downloader.NSIS.GJ
Ad-AwareTrojan.Downloader.NSIS.GJ
SophosMal/Generic-S (PUA)
ComodoMalware@#19z30tsuwx9ka
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeTrojan.Downloader.NSIS.GJ
EmsisoftTrojan.Downloader.NSIS.GJ (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.Swotter.hociy
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftTrojan:Win32/Spynoon.MXA!MTB
AegisLabTrojan.Win32.Noon.l!c
ZoneAlarmHEUR:Trojan-Spy.Win32.Noon.gen
GDataWin32.Trojan-Stealer.FormBook.9874D7
AhnLab-V3Malware/Win.Reputation.C4407086
McAfeeArtemis!BA55A2178283
MAXmalware (ai score=82)
VBA32TrojanSpy.Noon
MalwarebytesMalware.AI.4222468549
TrendMicro-HouseCallTROJ_GEN.F0D1C00D721
RisingTrojan.Kryptik!8.8 (CLOUD)
IkarusTrojan.NSIS.Agent
FortinetW32/Injector.EPBA!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HoMASSQA

How to remove Trojan:Win32/Spynoon.MXA!MTB?

Trojan:Win32/Spynoon.MXA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment