Spy Trojan

Trojan:Win32/SpyNoon.RVAH!MTB removal tips

Malware Removal

The Trojan:Win32/SpyNoon.RVAH!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SpyNoon.RVAH!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Trojan:Win32/SpyNoon.RVAH!MTB?


File Info:

name: 755B93294558AF97A148.mlw
path: /opt/CAPEv2/storage/binaries/c122639d652908b10751cb546a1c48e753427aa4d74f6a638fcb6c829b65e12f
crc32: B2A500B4
md5: 755b93294558af97a14841e9bc68e98f
sha1: 029109b124ed56ade655ed9a7fec6ea822c16339
sha256: c122639d652908b10751cb546a1c48e753427aa4d74f6a638fcb6c829b65e12f
sha512: 5bd98a51180bd74193de208f6ec76fb76dee3f084ac64cb9c3125d6364c4e30a2be848d834dfe921128a61dd49ef1c21ee197e8a6dca0ac3b1ca1a73fb5537b0
ssdeep: 24576:niZakGXsru5PAKhEqmlydutZUoEtdPg5b:niWcWfPg5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133159D52F2914E33C43B1A348C5B67A9582BBF432E187BC637E46D487E796813C296D3
sha3_384: 1d4432e5ff16ea8242db18a9d3b0d0857065482ff36c6a53475878d2e5756d999790a45bd4fe7fa0b34b2f178cce107d
ep_bytes: 558bec83c4f053b8300a4900e87730f7
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan:Win32/SpyNoon.RVAH!MTB also known as:

LionicTrojan.Win32.Remcos.m!c
MicroWorld-eScanTrojan.Agent.FUZH
FireEyeTrojan.Agent.FUZH
CAT-QuickHealTrojan.SpynoonIH.S27672054
McAfeeRDN/ModiLoader
CylanceUnsafe
VIPRETrojan.Agent.FUZH
SangforTrojan.Win32.Delf.DIB
K7AntiVirusTrojan-Downloader ( 0058298e1 )
AlibabaBackdoor:Win32/SpyNoon.6b32a148
K7GWTrojan-Downloader ( 0058298e1 )
VirITTrojan.Win32.Avemaria.DHG
CyrenW32/Delf.SK.gen!Eldorado
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Delf.DIB
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Ratx-9943686-0
KasperskyHEUR:Backdoor.Win32.Remcos.gen
BitDefenderTrojan.Agent.FUZH
NANO-AntivirusTrojan.Win32.DelfDownloader.joabzp
AvastWin32:RATX-gen [Trj]
TencentMalware.Win32.Gencirc.10d03860
Ad-AwareTrojan.Agent.FUZH
TACHYONBackdoor/W32.DP-Remcos.921088
SophosMal/Generic-S + Troj/Formbo-CPH
ComodoMalware@#27c6uhei7b0md
DrWebTrojan.DownLoader44.49615
ZillyaDownloader.Delf.Win32.62610
TrendMicroTrojanSpy.Win32.NOON.UHBAZCLSC
McAfee-GW-EditionRDN/ModiLoader
EmsisoftTrojan-Downloader.Delf (A)
GDataGeneric.Trojan.PSEB.RITPNS
JiangminBackdoor.NetWiredRC.bxn
WebrootW32.Malware.Gen
AviraTR/AD.DelfDownloader.rlhak
Antiy-AVLTrojan/Generic.ASMalwS.F7
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Agent.FUZH
ViRobotTrojan.Win32.Z.Sabsik.921088.B
MicrosoftTrojan:Win32/SpyNoon.RVAH!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R483839
ALYacTrojan.Agent.FUZH
MAXmalware (ai score=100)
VBA32BScope.Trojan.Hesv
MalwarebytesTrojan.MalPack.DLF
TrendMicro-HouseCallTrojanSpy.Win32.NOON.UHBAZCLSC
RisingDownloader.Agent!8.B23 (KTSE)
YandexTrojan.AvsArher.bXOk2q
IkarusTrojan.Inject
MaxSecureTrojan.Malware.9833444.susgen
FortinetW32/Injector.EQPQ!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/WLT.G
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/SpyNoon.RVAH!MTB?

Trojan:Win32/SpyNoon.RVAH!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment