Spy Trojan

About “Trojan-Spy.Win32.Noon.aroo” infection

Malware Removal

The Trojan-Spy.Win32.Noon.aroo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Noon.aroo virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Noon.aroo?


File Info:

crc32: FE1CCEF9
md5: a6eeff2abdcca09deca20d546bb1bd55
name: img.exe
sha1: e142a0f4f1e51bf4fde3ada362a0282d0eff518c
sha256: 77aba16d7f58982a5d24ccc93d9b90428b567a1df2d65a199755a3dfc9adb502
sha512: f412519aac305dec48023be79875960c4f6ecc4cb432f967353bfdd986aef64680232a91e4a48c1e18db3d249830ae0f988f40843d5f5db2c6f957fab867fb05
ssdeep: 24576:G66Y66xuy44l582154CxzzR60mWuU15JtKTDCnFBMciAOeTf:J4Jkx/tm6/JITDCnFBMnPg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.18362.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.18362.1
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Trojan-Spy.Win32.Noon.aroo also known as:

MicroWorld-eScanTrojan.GenericKD.32766166
FireEyeGeneric.mg.a6eeff2abdcca09d
CAT-QuickHealTrojan.IGENERIC
McAfeeArtemis!A6EEFF2ABDCC
ALYacTrojan.Agent.FormBook
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32766166
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4f1e51
SymantecTrojan Horse
ESET-NOD32Win32/Formbook.AA
AvastWin32:Trojan-gen
GDataWin32.Trojan-Stealer.FormBook.XAMEJR
KasperskyTrojan-Spy.Win32.Noon.aroo
NANO-AntivirusTrojan.Win32.Formbook.gkbcgg
ViRobotTrojan.Win32.Z.Swotter.1375232
EmsisoftTrojan.GenericKD.32766166 (B)
DrWebTrojan.Siggen8.58053
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
APEXMalicious
CyrenW32/Trojan.BGYM-1893
ArcabitTrojan.Generic.D1F3F8D6
AhnLab-V3Malware/Win32.Generic.C3608730
ZoneAlarmTrojan-Spy.Win32.Noon.aroo
MicrosoftTrojanSpy:Win32/Swotter.A!bit
Acronissuspicious
MAXmalware (ai score=81)
Ad-AwareTrojan.GenericKD.32766166
MalwarebytesSpyware.FormBook
PandaTrj/CI.A
ZonerTrojan.Win32.80900
IkarusTrojan.Win32.Formbook
FortinetW32/Formbook.AA!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Application.6b6

How to remove Trojan-Spy.Win32.Noon.aroo?

Trojan-Spy.Win32.Noon.aroo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment