Backdoor

Backdoor.Agent.NOIP removal guide

Malware Removal

The Backdoor.Agent.NOIP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.NOIP virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Backdoor.Agent.NOIP?


File Info:

name: 8A4D10B79FC5C941FA43.mlw
path: /opt/CAPEv2/storage/binaries/ff050dd274601817b8a050b8dc6dfd1d1b7656c10b13fbe810e9a50d4a6675bc
crc32: D6DB3A34
md5: 8a4d10b79fc5c941fa434f80d4f16e59
sha1: 1189f7a96fa7dbd37214bab63702db30da1a4811
sha256: ff050dd274601817b8a050b8dc6dfd1d1b7656c10b13fbe810e9a50d4a6675bc
sha512: 1fa4fa8af659e290295fbcfb3fd3cabef2769fa1249e0591f3157a276b503611e8252363b1d0606f7002ad9a1e1e46c6f163214bc3f56fea978bceaf038fb98e
ssdeep: 192:MDJkY5OMSJKNqOaV6nlYJLDkLT69TOjbvE:MDJkY5UNVfkLT69qE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T149F1E61163F042B2DBAF17721DA3AA115736E708CE77EF2F0580E2635D9B954CA52723
sha3_384: 3e12bc78714fd5d8c202bb24ebd64b046f82a40a692c18affd8363f3655d1343be28c47803c9ce8cd29b5c0f8498e7f1
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-05 00:10:22

Version Info:

Translation: 0x0000 0x04b0
Comments: Loading team
CompanyName: E-Stance Co.
FileDescription:
FileVersion: 1.0.0.0
InternalName: spoolsc.exe
LegalCopyright: Copyright 1998-2016
LegalTrademarks: Trademark 1998-2016
OriginalFilename: spoolsc.exe
ProductName: Help assembly
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Backdoor.Agent.NOIP also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Starter.5442
MicroWorld-eScanTrojan.Agent.BUDT
FireEyeGeneric.mg.8a4d10b79fc5c941
ALYacTrojan.Agent.BUDT
CylanceUnsafe
ZillyaTrojan.Tinba.Win32.4548
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004d342d1 )
K7GWTrojan ( 004d342d1 )
Cybereasonmalicious.79fc5c
BitDefenderThetaGen:NN.ZemsilF.34114.am0@a4Hgqpk
VirITTrojan.Win32.MSIL9.JFX
CyrenW32/MSIL_Kryptik.COX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.QSS
ClamAVWin.Malware.Budt-9798777-0
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderTrojan.Agent.BUDT
NANO-AntivirusTrojan.Win32.Starter.ebrjya
AvastWin32:CrypterX-gen [Trj]
Ad-AwareTrojan.Agent.BUDT
SophosML/PE-A
ComodoTrojWare.MSIL.Agent.FDC@6jjk0f
McAfee-GW-EditionTrojan-FJWU!8A4D10B79FC5
EmsisoftTrojan.Agent.BUDT (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Rogue.Gen
AviraHEUR/AGEN.1124834
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.16A6236
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.U.Agent.7680.B
GDataTrojan.Agent.BUDT
CynetMalicious (score: 99)
McAfeeTrojan-FJWU!8A4D10B79FC5
TACHYONTrojan/W32.DN-Agent.7680.X
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Agent.NOIP
APEXMalicious
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.QLP!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Backdoor.Agent.NOIP?

Backdoor.Agent.NOIP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment