Spy Trojan

What is “Trojan:Win32/Spynoon.PAY!MTB”?

Malware Removal

The Trojan:Win32/Spynoon.PAY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Spynoon.PAY!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family

How to determine Trojan:Win32/Spynoon.PAY!MTB?


File Info:

name: 27C08F7F1911B733BF29.mlw
path: /opt/CAPEv2/storage/binaries/8914ac5f2053aa939614fd8a33bfc801699662512d4c2a6dada77f0916e04f51
crc32: F752B29B
md5: 27c08f7f1911b733bf29119189831866
sha1: 2cbbd23ed88f20d152c7b99d9b8bcfa774fcebae
sha256: 8914ac5f2053aa939614fd8a33bfc801699662512d4c2a6dada77f0916e04f51
sha512: 1afa9c6099854c500b4089d583a7b6b262dd0ca007ff0574d872eff865e9a7dedcafe5897e759a448d01d588e35bd0e01027ba88e932532d0fa56b7c250574cf
ssdeep: 6144:ow4cB/R54JJOTv+gwEd+1sYq0DYNR5Uz1HsL56aKwjvuC:U+n47Oha1qG8kBS56aJt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19344121A35F0A4E3E8530EB038FB976ACFB422182B65039B77955FDF053A5C7A126247
sha3_384: cf4896739f3d68684bddcb432e62984d5d17d8d474ff42daa212cb0eeec232bbbb5ec645f589fd5acbdcb271658f52aa
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:48:57

Version Info:

0: [No Data]

Trojan:Win32/Spynoon.PAY!MTB also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38829192
FireEyeTrojan.GenericKD.38829192
ALYacTrojan.GenericKD.38829192
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.38829192
K7GWTrojan ( 0058d6621 )
K7AntiVirusTrojan ( 0058d6621 )
CyrenW32/Injector.ATR.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EQYW
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Generic.2abd9109
ViRobotTrojan.Win32.Z.Injector.256602
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareTrojan.GenericKD.38829192
SophosMal/Generic-S
ComodoMalware@#3kwcxetbp8raq
DrWebTrojan.Siggen16.38877
TrendMicroTROJ_FRS.VSNTAV22
McAfee-GW-EditionRDN/Formbook
EmsisoftTrojan.GenericKD.38829192 (B)
IkarusTrojan.NSIS.Agent
WebrootW32.Trojan.Risis.1
AviraTR/Injector.mcgpk
MAXmalware (ai score=83)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Spynoon.PAY!MTB
GridinsoftRansom.Win32.Sabsik.sa
SUPERAntiSpywareTrojan.Agent/Gen-AdInst
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.P93N18
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.ObfusInjector.R467391
McAfeeRDN/Formbook
VBA32Trojan.Sabsik.FL
MalwarebytesMalware.AI.3764160548
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.VSNTAV22
TencentNsis.Trojan.Risis.Htci
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.EQZR!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.f1911b
AvastWin32:PWSX-gen [Trj]

How to remove Trojan:Win32/Spynoon.PAY!MTB?

Trojan:Win32/Spynoon.PAY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment