Spy Trojan

Trojan-Spy.Win32.Noon.auzt removal tips

Malware Removal

The Trojan-Spy.Win32.Noon.auzt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Noon.auzt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Noon.auzt?


File Info:

crc32: 7F24808A
md5: 04da6ee4dc51f88598ebc5387b84a04b
name: elpatron.exe
sha1: f72bc977ffb00524e535c8b2f72ae878c57e9a5c
sha256: 76f4cc1e0789b5f34fd0c0b3c3addf0f3f001699476f44222c61e4d79d61957b
sha512: df08cb307a8d806f21d99dcc394d3eaf8c49735949230e92c19394a6aef043c2ab6a114bb0212df53922f70f0e754bebc99e5632176eeb0d012b82c7560ce49b
ssdeep: 768:ynN7/YOCaUnWB4XqkfSUWvcBmU7yR2wz:y5UO4XqkFWDUOD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
InternalName: Rummages5
FileVersion: 1.00
CompanyName: Unflappabl
Comments: BIQUINTI
ProductName: Vibetoite9
ProductVersion: 1.00
FileDescription: Pharyngot
OriginalFilename: Rummages5.exe

Trojan-Spy.Win32.Noon.auzt also known as:

MicroWorld-eScanGen:Variant.Babar.18456
FireEyeGen:Variant.Babar.18456
Qihoo-360Trojan.Generic
McAfeeFareit-FRM!04DA6EE4DC51
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00560b631 )
BitDefenderGen:Variant.Babar.18456
K7GWTrojan ( 00560b631 )
TrendMicroTROJ_GEN.R002C0DBI20
BitDefenderThetaGen:NN.ZevbaF.34090.dm0@aqklFLpb
F-ProtW32/Injector.YX.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.EKOR
TrendMicro-HouseCallTROJ_GEN.R002C0DBI20
AvastWin32:Trojan-gen
ClamAVWin.Dropper.LokiBot-7590003-0
GDataGen:Variant.Babar.18456
KasperskyTrojan-Spy.Win32.Noon.auzt
AlibabaTrojan:Win32/FormBook.08a3fb87
NANO-AntivirusTrojan.Win32.Noon.hberfq
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Trojan-spy.Noon.Glu
Ad-AwareGen:Variant.Babar.18456
EmsisoftGen:Variant.Babar.18456 (B)
F-SecureTrojan.TR/Injector.njkpx
DrWebTrojan.PackedENT.133
McAfee-GW-EditionFareit-FRM!04DA6EE4DC51
Trapminemalicious.high.ml.score
SophosMal/FareitVB-W
APEXMalicious
CyrenW32/Injector.YX.gen!Eldorado
WebrootW32.Trojan.Gen
AviraTR/Injector.njkpx
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Babar.D4818
ZoneAlarmTrojan-Spy.Win32.Noon.auzt
MicrosoftTrojan:Win32/FormBook.BS!MTB
VBA32BScope.Trojan.Azden
ALYacTrojan.Agent.FormBook
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
IkarusTrojan.VB.Crypt
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.EETV!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan-Spy.Win32.Noon.auzt?

Trojan-Spy.Win32.Noon.auzt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment