Spy Trojan

Should I remove “TrojanSpy:Win32/Noon!MSR”?

Malware Removal

The TrojanSpy:Win32/Noon!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Noon!MSR virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

qick.icu

How to determine TrojanSpy:Win32/Noon!MSR?


File Info:

crc32: 1CEB2938
md5: c874516208ce0c70646fecd3d851aab1
name: C874516208CE0C70646FECD3D851AAB1.mlw
sha1: 964fe2a12e368f05c6ec67279a23c634556c7de7
sha256: f8488eaf800c253ed79f6afbbc16e4182784c93263709a393767348ec096bfce
sha512: d5ef0e57a0c491f38e5b46751748ee0b4a69e878e7302091aac9c1b320ab4f41172d572f71eb56dea07fd6910a55f796f24c6ca68d64e5486d2c420a7c6f9125
ssdeep: 12288:ltukeGLqYslOeqWuZ2imKKwGvuPgyGCAM/1SOuq+fmKFQ1bYtK4rMgeQop:ltJNUk2IFgyGCzujVg8t/
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
FileVersion:
CompanyName: HTTrack
Comments: This installation was built with Inno Setup.
ProductName: WinHTTrack Website Copier
ProductVersion: 3.49.2
FileDescription: WinHTTrack Website Copier Setup
Translation: 0x0000 0x04b0

TrojanSpy:Win32/Noon!MSR also known as:

K7AntiVirusTrojan ( 005477cc1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.25642
CynetMalicious (score: 99)
ALYacGen:Variant.Graftor.558221
CylanceUnsafe
ZillyaTrojan.Gorgon.Win32.451
AlibabaTrojanPSW:Win32/Azorult.030c249d
K7GWTrojan ( 005477cc1 )
Cybereasonmalicious.208ce0
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EDNC
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Gorgon-6887794-0
KasperskyTrojan-PSW.Win32.Azorult.hsg
BitDefenderGen:Variant.Graftor.558221
NANO-AntivirusTrojan.Win32.Inject.fmuxzq
MicroWorld-eScanGen:Variant.Graftor.558221
TencentMalware.Win32.Gencirc.114d9a56
Ad-AwareGen:Variant.Graftor.558221
SophosMal/Generic-S
ComodoTrojWare.Win32.Delf.ED@7zqj8y
BitDefenderThetaGen:NN.ZelphiF.34266.6mKfaKbd7teI
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeGeneric.mg.c874516208ce0c70
EmsisoftGen:Variant.Graftor.558221 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Gorgon.av
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1117566
eGambitUnsafe.AI_Score_77%
Antiy-AVLTrojan/Generic.ASMalwS.2A8B20A
MicrosoftTrojanSpy:Win32/Noon!MSR
ArcabitTrojan.Graftor.D8848D
GDataGen:Variant.Graftor.558221
AhnLab-V3Malware/Win32.Generic.C414657
McAfeeArtemis!C874516208CE
MAXmalware (ai score=89)
VBA32BScope.Adware.Webalt
PandaTrj/GdSda.A
YandexTrojan.GenAsa!FlNyf0fu4KE
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.74129191.susgen
FortinetW32/GenKryptik.EKLE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove TrojanSpy:Win32/Noon!MSR?

TrojanSpy:Win32/Noon!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment