Backdoor

What is “Backdoor:MSIL/Noancooe!rfn”?

Malware Removal

The Backdoor:MSIL/Noancooe!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/Noancooe!rfn virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor:MSIL/Noancooe!rfn?


File Info:

crc32: 207349E1
md5: 6bb7e6d51a61deaaf510eeaf0c46a782
name: 6BB7E6D51A61DEAAF510EEAF0C46A782.mlw
sha1: c5a2aa6e8eab1f804a9044a8487db236ec644e32
sha256: dd79e4b17db7b1d1380b04103964e6e0a1b40981ad7e43b0f64c37055044c72b
sha512: 842f27d065861b84b4f0ac89c4296cd3fe9719256ff957562e741e06c57279bafc7445e562ee7e62ccf62ce353a505deca0a68bfe71d6b8b7cdf4fc7c7669ba0
ssdeep: 49152:t5hlPlg376r7aVMyi0pse7n2ZkP5ABINPPX580Vs9hcHCRHf8zh:jPqGr550172ZkPOKNHRVs9ai9uh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.00.2900.2180
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE
Translation: 0x0409 0x04b0

Backdoor:MSIL/Noancooe!rfn also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Trojan.Generic.20550245
FireEyeGeneric.mg.6bb7e6d51a61deaa
McAfeeArtemis!6BB7E6D51A61
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00509cdb1 )
BitDefenderDropped:Trojan.Generic.20550245
K7GWTrojan ( 00509cdb1 )
Cybereasonmalicious.51a61d
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.DarkComet-6305705-0
KasperskyTrojan.Win32.Yakes.svmj
NANO-AntivirusTrojan.Win32.Yakes.emwyfc
AegisLabTrojan.Win32.Yakes.4!c
RisingTrojan.Tiggre!8.ED98 (TFE:5:1jH2xj8ao4G)
Ad-AwareDropped:Trojan.Generic.20550245
SophosML/PE-A + Troj/MDrop-GWI
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebBackDoor.Comet.152
McAfee-GW-EditionGenericRXMC-ND!27134E4250B9
EmsisoftDropped:Trojan.Generic.20550245 (B)
IkarusTrojan.Win32.Injector
JiangminTrojan.Yakes.upo
WebrootW32.Trojan.Gen
AviraTR/AD.CeeInject.uqihx
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Yakes
KingsoftWin32.Troj.Yakes.sv.(kcloud)
MicrosoftBackdoor:MSIL/Noancooe!rfn
ArcabitTrojan.Generic.D1399265
ZoneAlarmTrojan.Win32.Yakes.svmj
GDataDropped:Trojan.Generic.20550245
CynetMalicious (score: 100)
BitDefenderThetaAI:Packer.38A275C423
VBA32Heur.Malware-Cryptor.Hlux
MalwarebytesMalware.AI.4128373425
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.DNAN
TencentWin32.Trojan.Yakes.Wsap
YandexTrojan.GenAsa!Gj0rfAWemFg
FortinetW32/Injector.DNAN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.277

How to remove Backdoor:MSIL/Noancooe!rfn?

Backdoor:MSIL/Noancooe!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment