Spy Trojan

Trojan:Win32/SpyNoon.PDL!MTB malicious file

Malware Removal

The Trojan:Win32/SpyNoon.PDL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SpyNoon.PDL!MTB virus can do?

  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Trojan:Win32/SpyNoon.PDL!MTB?


File Info:

name: 303036DB85A3D0F72A48.mlw
path: /opt/CAPEv2/storage/binaries/9930ad649d00adc91f50cd6644dc69cf8b7fb3d531d39a0a81efc23ceaebe15d
crc32: 5B15B4A9
md5: 303036db85a3d0f72a48b5803480af12
sha1: 6905cf190bdc3c93a0af6b5b3eee1fa344401712
sha256: 9930ad649d00adc91f50cd6644dc69cf8b7fb3d531d39a0a81efc23ceaebe15d
sha512: 84b82572ca951b51995553fe141f4f772ded39d4a2495a6df5a256ec897b7780f81853a630ea5c59e6880bcbc6efae070c4bbc2057839090fffd885f31502617
ssdeep: 6144:owIfaVnoDyXBu3a7kBbTS0nUoGavdukVwoCDCYp:blImu3MkBbTGavXwo8N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A44135F01C2E467F2131EB108BB7A2DE171A20417266BDB1B844F5AFD123E7EA056DE
sha3_384: d97a88c966528cec75dd10b472b2328d6ab9e0e7cb1c07b3e99ee01fb3c45cd7e32092f47bbaf7870bac1433adfcbdce
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:48:57

Version Info:

0: [No Data]

Trojan:Win32/SpyNoon.PDL!MTB also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38997781
FireEyeTrojan.GenericKD.38997781
ALYacTrojan.GenericKD.38997781
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 0058df101 )
AlibabaTrojan:Application/ObfusInjector.b81b9cc2
K7GWTrojan ( 0058df101 )
Cybereasonmalicious.b85a3d
CyrenW32/Injector.ATZ.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Win32/Injector.ERBE
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Cerbu-9938496-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.38997781
SUPERAntiSpywareTrojan.Agent/Gen-AdInst
AvastWin32:InjectorX-gen [Trj]
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareTrojan.GenericKD.38997781
SophosMal/Generic-S + Troj/Formbo-CBU
ComodoMalware@#3i1fgg45sakzi
DrWebTrojan.Inject4.25235
TrendMicroTROJ_GEN.R06BC0DB722
McAfee-GW-EditionTrojan-FUGN!C9042C2CB30C
EmsisoftTrojan.GenericKD.38997781 (B)
IkarusTrojan.NSIS.Agent
GDataTrojan.GenericKD.38997781
AviraTR/Injector.qddpl
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Injector.253576
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/SpyNoon.PDL!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.ObfusInjector.R467391
McAfeeArtemis!303036DB85A3
MAXmalware (ai score=80)
VBA32Trojan.Sabsik.FL
MalwarebytesMalware.AI.3756875677
TrendMicro-HouseCallTROJ_GEN.R06BC0DB722
TencentWin32.Trojan.Generic.Lfzk
YandexTrojan.Igent.bXqeeE.41
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.ERAJ!tr
AVGWin32:InjectorX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/SpyNoon.PDL!MTB?

Trojan:Win32/SpyNoon.PDL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment