Spy Trojan

Trojan:Win32/SpyNoon.OBC!MTB information

Malware Removal

The Trojan:Win32/SpyNoon.OBC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SpyNoon.OBC!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family

How to determine Trojan:Win32/SpyNoon.OBC!MTB?


File Info:

name: 60651F4050B51AEE586A.mlw
path: /opt/CAPEv2/storage/binaries/2e79796477ea1bbf8d60b6dc75ee72cf6cb19ac32bfa6653d8e51eec25dac6e3
crc32: 76CC20B7
md5: 60651f4050b51aee586a67c9515b8049
sha1: fb90f177bf6b58805ed91c8dc750d8eb7c446b23
sha256: 2e79796477ea1bbf8d60b6dc75ee72cf6cb19ac32bfa6653d8e51eec25dac6e3
sha512: 5253a022b2e26deebf7cfae81ad1f7d95a6753a7cd1708e78d59c05d9449f6af872218916e8263ad9ccc2b0088a12c672f65d350106ab6b4d1c488aa7a197ac6
ssdeep: 6144:owt+g21WiCHRY3aOPVRs9mRY6NMYsouTH7l119yX:hz0CHuaiKmC6VsHJ1SX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T158441266209AD9BBE48B17312EB6B7EAC3F7D7052857174B03A00BFFAD2508719244D6
sha3_384: 9e03f554c38d8fbab708b640aed29d90c4391fc426c376f00548c0fab4a422d169f0f5c99ed8ec7851ab2823941325ab
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:48:57

Version Info:

0: [No Data]

Trojan:Win32/SpyNoon.OBC!MTB also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.48104770
FireEyeTrojan.GenericKD.48104770
CAT-QuickHealTrojan.Spynoon
ALYacTrojan.GenericKD.48104770
CylanceUnsafe
K7AntiVirusTrojan ( 0058d7451 )
AlibabaTrojan:Application/ObfusInjector.f0370ac2
K7GWTrojan ( 0058d7451 )
Cybereasonmalicious.050b51
CyrenW32/Injector.ATR.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Win32/Injector.EQZF
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Trojan.Filerepmalware-9937610-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.48104770
SUPERAntiSpywareTrojan.Agent/Gen-AdInst
TencentWin32.Trojan-spy.Noon.Wlyz
Ad-AwareTrojan.GenericKD.48104770
SophosMal/Generic-S
DrWebTrojan.Siggen16.37820
TrendMicroTROJ_GEN.R06BC0DAS22
McAfee-GW-EditionNSIS/ObfusInjector.h
EmsisoftTrojan.GenericKD.48104770 (B)
Paloaltogeneric.ml
WebrootW32.Trojan.Gen
AviraTR/AD.Swotter.fexqa
MicrosoftTrojan:Win32/SpyNoon.OBC!MTB
GDataTrojan.GenericKD.48104770
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.ObfusInjector.R467391
McAfeeArtemis!60651F4050B5
MAXmalware (ai score=82)
VBA32Trojan.Sabsik.FL
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_GEN.R06BC0DAS22
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.Igent.bXmEMG.2
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.S!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/SpyNoon.OBC!MTB?

Trojan:Win32/SpyNoon.OBC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment