Spy Trojan

Trojan-Spy.Win32.Noon.badp removal guide

Malware Removal

The Trojan-Spy.Win32.Noon.badp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Noon.badp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to mimic the file extension of a JPG image by having ‘jpg’ in the file name.
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Noon.badp?


File Info:

crc32: 982D3875
md5: c289ec525b815c400eb88beb1f459489
name: Me.jpg.jpg.jpg.jpg.scr
sha1: ada3b9f684091350231c393962354c6c77c5695f
sha256: 6617979630def30c8a103baceedd1ddb972a53b984de91682aa93451faf833bb
sha512: 73a3bf81a64c2cfea278bdaaab397f1cc823453f3b48af8a0eca4afa9052bcb32df7f50cb8e9f5f248fa9ad3feb8ed04ad8de0516d8d752d122a928d6c29866b
ssdeep: 1536:q/F9RhueuFIWwqY3bri06oo4frRNtSX/0TFx:q/FgeuKWJ6PoUR60T7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: assemblere
InternalName: Skattefriheden
FileVersion: 1.00
LegalTrademarks: moliminous
ProductName: HOLMES
ProductVersion: 1.00
OriginalFilename: Skattefriheden.exe

Trojan-Spy.Win32.Noon.badp also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 85)
FireEyeGeneric.mg.c289ec525b815c40
McAfeeArtemis!C289EC525B81
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
AlibabaTrojan:Win32/Injector.78effc39
K7GWTrojan ( 0056c5881 )
Cybereasonmalicious.684091
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Graftor.814706
KasperskyTrojan-Spy.Win32.Noon.badp
BitDefenderGen:Variant.Graftor.814706
MicroWorld-eScanGen:Variant.Graftor.814706
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareGen:Variant.Graftor.814706
Comodo.UnclassifiedMalware@0
F-SecureHeuristic.HEUR/AGEN.1109934
SophosGeneric PUA KN (PUA)
IkarusWin32.Outbreak
eGambitUnsafe.AI_Score_92%
AviraHEUR/AGEN.1109934
ArcabitTrojan.Graftor.DC6E72
ZoneAlarmTrojan-Spy.Win32.Noon.badp
MicrosoftTrojan:Win32/Caynamer.A!ml
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.34152.gm0@ayQjr2ib
ALYacGen:Variant.Graftor.814706
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack.VB
ESET-NOD32a variant of Win32/Injector.EMZA
TrendMicro-HouseCallTROJ_GEN.R002H09HC20
FortinetW32/Kryptik.EQBY!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.Spy.7bb

How to remove Trojan-Spy.Win32.Noon.badp?

Trojan-Spy.Win32.Noon.badp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment