Spy Trojan

Trojan-Spy.Win32.Noon.bbuq information

Malware Removal

The Trojan-Spy.Win32.Noon.bbuq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Noon.bbuq virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

a.tmp.ninja
apps.identrust.com
crl.identrust.com
x1.c.lencr.org

How to determine Trojan-Spy.Win32.Noon.bbuq?


File Info:

crc32: 4F639CC0
md5: 563881f7f134da5443d3457a2f983f36
name: 563881F7F134DA5443D3457A2F983F36.mlw
sha1: 1d7807b9bd58d570b5b8a257c7f2e10288f00657
sha256: 7349ec9af1459457912535f50d1ad9a73887e2ee95d2b295674e1dcd9205c8c3
sha512: ee0392a8518f0dce51b70c64e23f475f0a0009b5700d6169f100b0b961281ae1ee9827f4a8c9b314e2e1894fc6e76afc9b8572ee29eb21dc2991cbf4710e827a
ssdeep: 12288:kXe9PPlowWX0t6mOQwg1Qd15CcYk0We1VkE70D8SSSSSSSSSSSSSSSSSSSSSSSS:BhloDX0XOf4PL7vSSSSSSSSSSSSSSSS
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

Trojan-Spy.Win32.Noon.bbuq also known as:

K7AntiVirusTrojan-Downloader ( 005817901 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37503988
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan-Downloader ( 005817901 )
Cybereasonmalicious.9bd58d
CyrenW32/AutoIt.VA.gen!Eldorado
ESET-NOD32Win32/TrojanDownloader.Agent.FVC
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Spy.Win32.Noon.bbuq
BitDefenderTrojan.GenericKD.37503988
MicroWorld-eScanTrojan.GenericKD.37503988
Ad-AwareTrojan.GenericKD.37503988
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.hc
FireEyeGeneric.mg.563881f7f134da54
EmsisoftTrojan.GenericKD.37503988 (B)
JiangminTrojan.Generic.dmcld
AviraTR/Dldr.Agent.uxkao
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/StopCrypt!ml
ArcabitTrojan.Generic.D23C43F4
ZoneAlarmTrojan-Spy.Win32.Noon.bbuq
GDataTrojan.GenericKD.37503988
AhnLab-V3Trojan/Win.Generic.C4620282
McAfeeArtemis!563881F7F134
MAXmalware (ai score=88)
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
YandexTrojan.Igent.bWuWFg.4
IkarusTrojan.Autoit
FortinetAutoIt/Injector.BFC6!tr
AVGWin32:Malware-gen

How to remove Trojan-Spy.Win32.Noon.bbuq?

Trojan-Spy.Win32.Noon.bbuq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment