Categories: SpyTrojan

Should I remove “TrojanSpy:Win32/Noon!MSR”?

The TrojanSpy:Win32/Noon!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Noon!MSR virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

qick.icu

How to determine TrojanSpy:Win32/Noon!MSR?


File Info:

crc32: 1CEB2938md5: c874516208ce0c70646fecd3d851aab1name: C874516208CE0C70646FECD3D851AAB1.mlwsha1: 964fe2a12e368f05c6ec67279a23c634556c7de7sha256: f8488eaf800c253ed79f6afbbc16e4182784c93263709a393767348ec096bfcesha512: d5ef0e57a0c491f38e5b46751748ee0b4a69e878e7302091aac9c1b320ab4f41172d572f71eb56dea07fd6910a55f796f24c6ca68d64e5486d2c420a7c6f9125ssdeep: 12288:ltukeGLqYslOeqWuZ2imKKwGvuPgyGCAM/1SOuq+fmKFQ1bYtK4rMgeQop:ltJNUk2IFgyGCzujVg8t/type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: FileVersion: CompanyName: HTTrack Comments: This installation was built with Inno Setup.ProductName: WinHTTrack Website Copier ProductVersion: 3.49.2 FileDescription: WinHTTrack Website Copier Setup Translation: 0x0000 0x04b0

TrojanSpy:Win32/Noon!MSR also known as:

K7AntiVirus Trojan ( 005477cc1 )
Elastic malicious (high confidence)
DrWeb Trojan.PWS.Stealer.25642
Cynet Malicious (score: 99)
ALYac Gen:Variant.Graftor.558221
Cylance Unsafe
Zillya Trojan.Gorgon.Win32.451
Alibaba TrojanPSW:Win32/Azorult.030c249d
K7GW Trojan ( 005477cc1 )
Cybereason malicious.208ce0
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Injector.EDNC
APEX Malicious
Avast Win32:Malware-gen
ClamAV Win.Trojan.Gorgon-6887794-0
Kaspersky Trojan-PSW.Win32.Azorult.hsg
BitDefender Gen:Variant.Graftor.558221
NANO-Antivirus Trojan.Win32.Inject.fmuxzq
MicroWorld-eScan Gen:Variant.Graftor.558221
Tencent Malware.Win32.Gencirc.114d9a56
Ad-Aware Gen:Variant.Graftor.558221
Sophos Mal/Generic-S
Comodo TrojWare.Win32.Delf.ED@7zqj8y
BitDefenderTheta Gen:NN.ZelphiF.34266.6mKfaKbd7teI
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition BehavesLike.Win32.Dropper.dc
FireEye Generic.mg.c874516208ce0c70
Emsisoft Gen:Variant.Graftor.558221 (B)
SentinelOne Static AI – Malicious PE
Jiangmin Trojan.Gorgon.av
Webroot W32.Adware.Gen
Avira HEUR/AGEN.1117566
eGambit Unsafe.AI_Score_77%
Antiy-AVL Trojan/Generic.ASMalwS.2A8B20A
Microsoft TrojanSpy:Win32/Noon!MSR
Arcabit Trojan.Graftor.D8848D
GData Gen:Variant.Graftor.558221
AhnLab-V3 Malware/Win32.Generic.C414657
McAfee Artemis!C874516208CE
MAX malware (ai score=89)
VBA32 BScope.Adware.Webalt
Panda Trj/GdSda.A
Yandex Trojan.GenAsa!FlNyf0fu4KE
Ikarus Trojan-Spy.Agent
MaxSecure Trojan.Malware.74129191.susgen
Fortinet W32/GenKryptik.EKLE!tr
AVG Win32:Malware-gen
Paloalto generic.ml

How to remove TrojanSpy:Win32/Noon!MSR?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “Malware.AI.1865006162”?

The Malware.AI.1865006162 is considered dangerous by lots of security experts. When this infection is active,…

24 mins ago

Trojan.Win32.Agent.xbnsym removal guide

The Trojan.Win32.Agent.xbnsym is considered dangerous by lots of security experts. When this infection is active,…

39 mins ago

Backdoor:Win32/AsyncRAT removal tips

The Backdoor:Win32/AsyncRAT is considered dangerous by lots of security experts. When this infection is active,…

45 mins ago

Win32:VB-NPD [Wrm] removal instruction

The Win32:VB-NPD [Wrm] is considered dangerous by lots of security experts. When this infection is…

54 mins ago

About “Symmi.4579” infection

The Symmi.4579 is considered dangerous by lots of security experts. When this infection is active,…

55 mins ago

What is “Lazy.487114”?

The Lazy.487114 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago