Spy Trojan

Trojan:Win32/SpyNoon.SSS!MTB removal

Malware Removal

The Trojan:Win32/SpyNoon.SSS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SpyNoon.SSS!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/SpyNoon.SSS!MTB?


File Info:

name: 594284BC779075142A6B.mlw
path: /opt/CAPEv2/storage/binaries/65d87f7599317ae1a8d7aa3503cc2aa675ee53ce7bfac384f4cc7b76339cc1ef
crc32: D1A40CB4
md5: 594284bc779075142a6b6665fa860ead
sha1: c88326e5a278880436a0af8f29ea0c7f7614e3aa
sha256: 65d87f7599317ae1a8d7aa3503cc2aa675ee53ce7bfac384f4cc7b76339cc1ef
sha512: 931bb72ed20113c56f250395e43e83c7f7045360f9fde91798d2cb8a5342448a4df3691ac6728a13554a9c367272e44ef1ac2b10169c9f3b06a004527949bd85
ssdeep: 6144:rGiDcMl332W2VBTYxoOyZan3uykbU1HsMar74K8ACUaiV4C1iiKw+qLh:HcM32TVyxzyij1MLIqFb+qLh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F64125767C04C3BC0E1DDF446BBE728F7BBE1861A323AA70BD42F69760291B5D85640
sha3_384: 2d7fc28db2aa311e66076c753bcbe5a40a68821695043a1f495b1000003d158b0f814d043905301d369aa21aa5eefc7c
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Trojan:Win32/SpyNoon.SSS!MTB also known as:

DrWebTrojan.Siggen16.514
MicroWorld-eScanTrojan.GenericKD.38214125
FireEyeTrojan.GenericKD.38214125
CAT-QuickHealTrojanspy.Noon
McAfeeRDN/Generic PWS.y
CylanceUnsafe
K7AntiVirusTrojan ( 0052eef11 )
AlibabaTrojanSpy:Win32/SpyNoon.251869e1
K7GWTrojan ( 0052eef11 )
Cybereasonmalicious.c77907
CyrenW32/Injector.AQQ.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32Win32/Formbook.AA
TrendMicro-HouseCallTROJ_FRS.0NA103L921
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
BitDefenderTrojan.GenericKD.38214125
AvastWin32:PWSX-gen [Trj]
Ad-AwareTrojan.GenericKD.38214125
EmsisoftTrojan.GenericKD.38214125 (B)
ComodoTrojWare.Win32.UMal.tgday@0
McAfee-GW-EditionRDN/Generic PWS.y
SophosMal/Generic-S + Troj/Formbo-BTQ
GDataWin32.Trojan-Stealer.FormBook.Y2N7W6
WebrootW32.Trojan.Gen
AviraTR/Formbook.rrsaw
MAXmalware (ai score=85)
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/SpyNoon.SSS!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.SpyNoon.C4826111
VBA32TrojanSpy.Noon
ALYacTrojan.Agent.FormBook
MalwarebytesMalware.AI.2951221103
APEXMalicious
IkarusTrojan.Win32.Injector
FortinetW32/Kryptik.AQQ!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A

How to remove Trojan:Win32/SpyNoon.SSS!MTB?

Trojan:Win32/SpyNoon.SSS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment