Spy Trojan

Trojan-Spy.Win32.Noon.araa malicious file

Malware Removal

The Trojan-Spy.Win32.Noon.araa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Noon.araa virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Urdu (Pakistan)
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Spy.Win32.Noon.araa?


File Info:

crc32: 929F149A
md5: 772ac8c8a2e770092e9394c2212605c6
name: win.exe
sha1: 805fea9deed20a3e7a0ecd80513c2462e84d1b3f
sha256: a6346505b1bc3d2b3cfbdbb2c03934be512206b69a940a8ae9c3900eaa78b03a
sha512: 830b8f3de8900aff4b3cd9a5d34ae6a1f5e66a44c8b25bd3701304bed33b081e0132465ac44b8729c4482abbbc424527b1b1907b7e258612b1d8a088955864d8
ssdeep: 6144:NYVWqmVdSN3SVFBQVSmekqBGDy9gALLOm/Hn8aw/OsY/Os:mYVG8zQVt8BGDy9nLXm/OsY/Os
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: koerljk
FileVersion: 1.00
OriginalFilename: koerljk.exe
ProductName: Doea

Trojan-Spy.Win32.Noon.araa also known as:

MicroWorld-eScanTrojan.GenericKD.32763464
FireEyeTrojan.GenericKD.32763464
ALYacTrojan.Agent.FormBook
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32763464
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZevbaF.32515.Cm0@au6pDnoO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.DYSS
TrendMicro-HouseCallTROJ_GEN.R002H06KR19
Paloaltogeneric.ml
GDataTrojan.GenericKD.32763464
KasperskyTrojan-Spy.Win32.Noon.araa
Ad-AwareTrojan.GenericKD.32763464
SophosMal/Generic-S
DrWebTrojan.Siggen8.58044
VIPREBackdoor.VB.Tofsee.f (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
SentinelOneDFI – Suspicious PE
Trapminemalicious.moderate.ml.score
CyrenW32/Trojan.PUWQ-6660
ArcabitTrojan.Generic.D1F3EE48
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmTrojan-Spy.Win32.Noon.araa
MicrosoftTrojan:Win32/Fuery.C!cl
AhnLab-V3Win-Trojan/VBKrand.Gen
Acronissuspicious
McAfeeFareit-FQG!772AC8C8A2E7
MAXmalware (ai score=85)
MalwarebytesTrojan.Crypt
IkarusWin32.Outbreak
AVGFileRepMalware
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM03.0.81F7.Malware.Gen

How to remove Trojan-Spy.Win32.Noon.araa?

Trojan-Spy.Win32.Noon.araa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment