Spy Trojan

Trojan:Win32/Spynoon.PAQ!MTB removal guide

Malware Removal

The Trojan:Win32/Spynoon.PAQ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Spynoon.PAQ!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family

How to determine Trojan:Win32/Spynoon.PAQ!MTB?


File Info:

name: E4133AFBA26EFDE5B019.mlw
path: /opt/CAPEv2/storage/binaries/b30e2fa345e02eecf58f3672cab4f07b4c6f84712c7dee9a64ca3005ac7bf255
crc32: 1BB47694
md5: e4133afba26efde5b01959df65c3eeb4
sha1: ea2b48d0f50918e47b4657fd5774c2766c640f0a
sha256: b30e2fa345e02eecf58f3672cab4f07b4c6f84712c7dee9a64ca3005ac7bf255
sha512: 563b0a1c9663c7c8a768ca6a50e8a27aa775a15282bf9dc00dc03d24ce8114a4c521d250e8ca49dea05549b791806dcd91bb856f8aa725155b2d52c19f7392ba
ssdeep: 6144:rGiurRinBoiRshFZ+s9q5M8SQAcXTZtrhrQ5P5yVaCFB1KrAt22EmNCtI5nK0wOu:VBVRsBuKZc1Ba5BKJQnmNCtI0t5Nxpx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178A4233A33D0DE77D001CB311072B9E7A7FDA5540329DA5D07D1ADEA2AA9CAE4C1C693
sha3_384: 357f58c2994cf8d39c5dcdcf7c67ef8429a99c48634ecefb8fa39388c38adbd74130d9e1cda715116284b97a09509a5e
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Trojan:Win32/Spynoon.PAQ!MTB also known as:

LionicTrojan.Win32.Risis.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47714989
FireEyeTrojan.GenericKD.47714989
McAfeeRDN/Formbook
CylanceUnsafe
K7AntiVirusTrojan ( 0058bf681 )
AlibabaTrojan:Win32/Spynoon.6f1a7b3f
K7GWTrojan ( 0058bf681 )
Cybereasonmalicious.ba26ef
CyrenW32/Injector.ASH.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EQUF
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Inject.gen
BitDefenderTrojan.GenericKD.47714989
NANO-AntivirusTrojan.Win32.Noon.jjiisz
AvastWin32:Trojan-gen
TencentWin32.Trojan.Inject.Ahdz
Ad-AwareTrojan.GenericKD.47714989
SophosMal/Generic-S
Comodofls.noname@0
DrWebTrojan.Siggen16.8984
TrendMicroTROJ_FRS.0NA103LJ21
McAfee-GW-EditionRDN/Formbook
EmsisoftTrojan.GenericKD.47714989 (B)
IkarusTrojan.Win32.Injector
GDataWin32.Trojan-Stealer.FormBook.YIT3K6
JiangminTrojan.Inject.cbvy
WebrootW32.Trojan.Risis.1
Antiy-AVLTrojan/Win32.Injector
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftTrojan.Win32.Downloader.sa
ArcabitTrojan.Generic.D2D812AD
MicrosoftTrojan:Win32/Spynoon.PAQ!MTB
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.47714989
MAXmalware (ai score=86)
VBA32Trojan.Inject
MalwarebytesMalware.AI.4230344546
TrendMicro-HouseCallTROJ_FRS.0NA103LJ21
YandexTrojan.Inject!bSDJyKCq3Ps
FortinetW32/Injector.EQUC!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Spynoon.PAQ!MTB?

Trojan:Win32/Spynoon.PAQ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment