Spy Trojan

Trojan:Win32/SpyNoon.RVC!MTB removal guide

Malware Removal

The Trojan:Win32/SpyNoon.RVC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SpyNoon.RVC!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/SpyNoon.RVC!MTB?


File Info:

crc32: 72430624
md5: 6e1d04aa8661ab43eb6ee6fa2fff960f
name: 6E1D04AA8661AB43EB6EE6FA2FFF960F.mlw
sha1: 9e3d96d954c00b032669aad61bb9ab308570823e
sha256: c5209d3ef6131477df386baba66bba2f086d6d6625cb4164bb6e25af5c5b05f8
sha512: fa6b7fbc651580ed5310e3be58d1337b6dacabb103c376b900b912abeddd9aee15b9bfeed257e802f9e9fadd303d3a7395efe730e055be9078d755be0646e3a0
ssdeep: 12288:xHBgbWCLg0YJpNC3P8EHs9B8WefX08Pe0000000000000000000000000000000:xqVg0YJpN2PhQRAhe00000000000000
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/SpyNoon.RVC!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057eda61 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.23058
ALYacGen:Variant.Zusy.391441
ZillyaTrojan.Injector.Win32.1045003
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Injector.b47da0e3
K7GWTrojan ( 0057eda61 )
CyrenW32/Delf.CFOG-6738
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPQR
APEXMalicious
AvastWin32:PWSX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Bingoml.gen
BitDefenderGen:Variant.Zusy.391441
MicroWorld-eScanGen:Variant.Zusy.391441
Ad-AwareGen:Variant.Zusy.391441
BitDefenderThetaGen:NN.ZelphiF.34790.NGW@a4hI@7ei
TrendMicroTROJ_GEN.R005C0DG621
McAfee-GW-EditionBehavesLike.Win32.DealPly.jh
FireEyeGeneric.mg.6e1d04aa8661ab43
EmsisoftGen:Variant.Zusy.391441 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Bingoml.ahr
AviraHEUR/AGEN.1143401
MicrosoftTrojan:Win32/SpyNoon.RVC!MTB
ZoneAlarmHEUR:Trojan.Win32.Bingoml.gen
GDataGen:Variant.Zusy.391441
AhnLab-V3Trojan/Win.Generic.C4541013
McAfeeGenericRXPD-LK!6E1D04AA8661
MAXmalware (ai score=84)
VBA32Trojan.Bingoml
MalwarebytesMalware.AI.4283351253
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R005C0DG621
RisingTrojan.Kryptik!1.D2D5 (CLASSIC)
IkarusTrojan.Win32.Bublik
MaxSecureTrojan.Malware.109135027.susgen
FortinetW32/Injector.EPQR!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASX0A

How to remove Trojan:Win32/SpyNoon.RVC!MTB?

Trojan:Win32/SpyNoon.RVC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment