Trojan

TrojanDownloader:Win32/Nonaco.J removal guide

Malware Removal

The TrojanDownloader:Win32/Nonaco.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Nonaco.J virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Nonaco.J?


File Info:

name: D9C2A5726F6D6293D5BE.mlw
path: /opt/CAPEv2/storage/binaries/1d090aa5c30253096e442abde44aa435675a351af7e55dd39c7bbec975951a2c
crc32: F4DE5C43
md5: d9c2a5726f6d6293d5beda3f12e3a40a
sha1: 19c80a54804e54a099ca61df28cdf5f6e8c0720d
sha256: 1d090aa5c30253096e442abde44aa435675a351af7e55dd39c7bbec975951a2c
sha512: 974eb4540c05156f92e6409e3314ad0813653e4b5a96c760359696eb025d49c2426b498c10a8912a70711f7e640fb817a83de32cc7a63889e37eec25fe59ac04
ssdeep: 384:L92iDI1qqqqqqqqqhSjaDoCVWi0elw4qI8AeyeS7v3I5QXiDckhsoYkwIxHfjIgv:L9DDI1qqqqqqqqqhjAqwEGSk1wIdfsgv
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T17BA28C0F0444E66EF88320F739A3E2372C418D346D21B28A09DE8BDD73B5E51DE695DA
sha3_384: 64e8ad7b7e579f1ef4fd4274d60ca79bfabd8ccae89827cf2021d8194eeeb9331265d928771a891341f5b7e6532f24f3
ep_bytes: 5589e583ec5cc745a400000000c745a8
timestamp: 2008-03-14 11:36:42

Version Info:

0: [No Data]

TrojanDownloader:Win32/Nonaco.J also known as:

LionicTrojan.Win32.Zirit.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.d9c2a5726f6d6293
CAT-QuickHealTjnDroppr.Zirit.S190393
SkyhighBehavesLike.Win32.Downloader.mc
McAfeeGeneric Spy.j
Cylanceunsafe
ZillyaTrojan.Generic.Win32.144507
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDropper:Win32/Zirit.30830d94
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BaiduWin32.Trojan-Dropper.Agent.by
VirITAdware.Vapsup.A
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDropper.Agent.EYA
APEXMalicious
ClamAVWin.Dropper.Agent-53973
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Dropper.Zirit.A
NANO-AntivirusTrojan.Win32.Agent.lxii
MicroWorld-eScanTrojan.Dropper.Zirit.A
TencentMalware.Win32.Gencirc.14006a3b
SophosMal/Behav-201
F-SecureTrojan.TR/Shell.Eviell
DrWebTrojan.MulDrop.14031
VIPRETrojan.Dropper.Zirit.A
TrendMicroTROJ_KRYPT.SME5
Trapminemalicious.high.ml.score
EmsisoftTrojan.Dropper.Zirit.A (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Dropper.Zirit.A
JiangminTrojanDropper.Agent.ifr
WebrootW32.Downloader.Gen
GoogleDetected
AviraTR/Shell.Eviell
Antiy-AVLTrojan[Dropper]/Win32.Agent
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.TrojanDropper.Agent.EYA@tn9
ArcabitTrojan.Dropper.Zirit.A
ViRobotDropper.Agent.23258
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDownloader:Win32/Nonaco.J
VaristW32/Risk.SMOK-7332
AhnLab-V3Trojan/Win32.Agent.R4031
VBA32TrojanDropper.Agent
ALYacTrojan.Dropper.Zirit.A
MAXmalware (ai score=100)
PandaTrj/Downloader.TCC
TrendMicro-HouseCallTROJ_KRYPT.SME5
RisingTrojan.Win32.Runie.a (CLASSIC)
YandexTrojan.GenAsa!n7/IGeaeLXU
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Agent.EYA!tr
BitDefenderThetaAI:Packer.00988FBF21
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Zirit.A

How to remove TrojanDownloader:Win32/Nonaco.J?

TrojanDownloader:Win32/Nonaco.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment