Spy Trojan

Trojan-Spy.Win32.Noon.amth removal instruction

Malware Removal

The Trojan-Spy.Win32.Noon.amth is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Noon.amth virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Spy.Win32.Noon.amth?


File Info:

name: E644933DB6482EA28F9B.mlw
path: /opt/CAPEv2/storage/binaries/d97ac3a7df23e1a12a597116e373692bb91e675497303d9f91a9a736b25712bf
crc32: F5B236AE
md5: e644933db6482ea28f9bc7c935f89061
sha1: 86194e1c8a54a0ae29fa7e004ef075d36a727c93
sha256: d97ac3a7df23e1a12a597116e373692bb91e675497303d9f91a9a736b25712bf
sha512: e55f326f2a58a07a8cb044a6dc6ea78f380f4fc9c7f8cb738ecec8fc2471e9529f24b874bf4f14eef671405c12007981e16c4e3ddb7d7dbe8b1d6be9abdc9743
ssdeep: 12288:nkcVOiJa9U687iK4QdGh4fenkfdtYw26i6a9:kcVOiJ4dK4QGyenGy6i6a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CE255BDA76BEF4B8C116FE3A238489ED9D593DB247291496FA043F33AA354110F64E34
sha3_384: 18d3a01d422c46723bb04169918bb78ce629ddbf60cba734bacc036c8c83a2f7b385ce33d9ce6cf2634db3d0d21a594c
ep_bytes: 685cf04900e8f0ffffff000000000000
timestamp: 2019-09-25 02:30:08

Version Info:

Translation: 0x0409 0x04b0
CompanyName: PAnDORATV
ProductName: suc_
FileVersion: 4.09.0002
ProductVersion: 4.09.0002
InternalName: gorgilox
OriginalFilename: gorgilox.exe

Trojan-Spy.Win32.Noon.amth also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.!m0@iWpeLEhi
ClamAVWin.Dropper.Fareit-7191424-0
FireEyeGeneric.mg.e644933db6482ea2
ALYacSpyware.Noon.gen
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Heur.PonyStealer.!m0@iWpeLEhi
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0052eef11 )
AlibabaTrojanSpy:Win32/Formbook.1f93e931
K7GWTrojan ( 0052eef11 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.VBZenPack_Heur
CyrenW32/Injector.RY.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Formbook.AA
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan-Spy.Win32.Noon.amth
BitDefenderGen:Heur.PonyStealer.!m0@iWpeLEhi
NANO-AntivirusTrojan.Win32.Noon.gbbhqz
AvastWin32:Trojan-gen
TencentWin32.Trojan-Spy.Noon.Zimw
EmsisoftGen:Heur.PonyStealer.!m0@iWpeLEhi (B)
F-SecureHeuristic.HEUR/AGEN.1362478
DrWebTrojan.PWS.Banker1.35359
ZillyaTrojan.Noon.Win32.10733
McAfee-GW-EditionFareit-FPP!E644933DB648
SophosMal/FareitVB-X
GDataGen:Heur.PonyStealer.!m0@iWpeLEhi
JiangminTrojanSpy.Noon.kcb
WebrootW32.Malware.Mlpe
AviraHEUR/AGEN.1362478
MAXmalware (ai score=82)
Antiy-AVLTrojan[Spy]/Win32.Noon
ArcabitTrojan.PonyStealer.E807DA
ZoneAlarmTrojan-Spy.Win32.Noon.amth
MicrosoftTrojanSpy:Win32/Swotter.A!rfn
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C3478296
McAfeeFareit-FPP!E644933DB648
Cylanceunsafe
PandaTrj/GdSda.A
RisingSpyware.Noon!8.E7C9 (CLOUD)
YandexTrojan.GenAsa!nn0BCYfqUXo
IkarusTrojan.Win32.Krypt
FortinetW32/Injector.EILY!tr
BitDefenderThetaGen:NN.ZevbaF.36350.!m0@aWpeLEhi
AVGWin32:Trojan-gen
Cybereasonmalicious.db6482
DeepInstinctMALICIOUS

How to remove Trojan-Spy.Win32.Noon.amth?

Trojan-Spy.Win32.Noon.amth removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment