Spy Trojan

Trojan:Win32/SpyNoon.SS!MTB malicious file

Malware Removal

The Trojan:Win32/SpyNoon.SS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SpyNoon.SS!MTB virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Bulgarian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/SpyNoon.SS!MTB?


File Info:

crc32: 60651A59
md5: b1ecea52d79c21a7b2665842b3e5f0de
name: B1ECEA52D79C21A7B2665842B3E5F0DE.mlw
sha1: 0f49f8b0213100fbe1988863db31526353eb9fea
sha256: 8f60ca9ce75139fa93a5ccd36c152e4675e35797fe5ebf5c7d863ea822a5f903
sha512: 75d0dc25154794d1afd7fb83a25ba59f8509d1b4ac6910f57ddc29508f5f80b8f5b8482385edd9d0166056c768861f136d32f6649f8ab42f8a42c28006e3b505
ssdeep: 6144:xMLfMw1qOevlL8cvTIa34DWv45MCePLnM7umwXS:YfMw1qhNJM1n5sQ7umwXS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: MagCoords2
FileVersion: 1.00
CompanyName: RR
ProductName: MagCoords2
ProductVersion: 1.00
OriginalFilename: MagCoords2.exe

Trojan:Win32/SpyNoon.SS!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.78095
FireEyeGeneric.mg.b1ecea52d79c21a7
ALYacGen:Variant.Midie.78095
MalwarebytesTrojan.MalPack
K7AntiVirusTrojan ( 0056c7a61 )
BitDefenderGen:Variant.Midie.78095
K7GWTrojan ( 0056c7a61 )
Cybereasonmalicious.2d79c2
BitDefenderThetaGen:NN.ZevbaF.34700.Fm3@a8kYPJlO
CyrenW32/Trojan.KOJJ-1436
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Generic-6664545-0
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/SpyNoon.88441864
TencentWin32.Trojan.Dropper.Pgcy
Ad-AwareGen:Variant.Midie.78095
SophosML/PE-A
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.VbCrypt.250
TrendMicroTROJ_GEN.R06CC0DLV20
McAfee-GW-EditionBehavesLike.Win32.VBObfus.hh
EmsisoftGen:Variant.Midie.78095 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Injector
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/SpyNoon.SS!MTB
GridinsoftTrojan.Win32.Agent.oa!s1
ArcabitTrojan.Midie.D1310F
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Midie.78095
CynetMalicious (score: 90)
McAfeeArtemis!B1ECEA52D79C
VBA32Malware-Cryptor.VB.gen.1
ESET-NOD32a variant of Win32/Injector.EMZT
TrendMicro-HouseCallTROJ_GEN.R06CC0DLV20
RisingDropper.Generic!8.35E (TFE:4:UU5REmsRv3Q)
IkarusWin32.Outbreak
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.BSHM!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM41.1.4AE7.Malware.Gen

How to remove Trojan:Win32/SpyNoon.SS!MTB?

Trojan:Win32/SpyNoon.SS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment