Spy Trojan

Trojan:Win32/SpyNoon!MSR removal tips

Malware Removal

The Trojan:Win32/SpyNoon!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SpyNoon!MSR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • CAPE detected the Formbook malware family
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/SpyNoon!MSR?


File Info:

name: 7C875245A2618B56AD9F.mlw
path: /opt/CAPEv2/storage/binaries/a81f4b0d0e1d5cc93e06323610f8500c2f0a0b5c15c890c104e3234bfee7fa68
crc32: 474DFB08
md5: 7c875245a2618b56ad9f9ee5b11bc6c8
sha1: d23a6f84cf4a444e3c682be2b4f93c7a939c92ce
sha256: a81f4b0d0e1d5cc93e06323610f8500c2f0a0b5c15c890c104e3234bfee7fa68
sha512: 716d02cd9ecf62436e28c883111dbc3b83f8d9d10f5dec895cb69f8d8c070a85d5205312fdbecb081f062477f0c24b983df16d3d9057043fb9bd7b1022673662
ssdeep: 12288:iRnGW2kdxm7TNt9KeybAt1PSsczzGl5TYM2Dx:lcxm7TNt9Ke4E4ml5TYNl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159C401553B88DE1BD78122BD5AF0D339A7B49D881D16C713ABE43E9FBE2EAD12C00151
sha3_384: 83bc23a7ce7b0f4447ce5d4665a139e3dc07072a2680fb6e159edc7820538d1153054f7fc171449b02f81d3fdf295b48
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Trojan:Win32/SpyNoon!MSR also known as:

LionicTrojan.Win32.Androm.4!c
MicroWorld-eScanTrojan.GenericKD.38041556
FireEyeTrojan.GenericKD.38041556
CAT-QuickHealTrojan.IGENERIC
ALYacTrojan.GenericKD.38041556
SangforTrojan.Win32.Noon.gen
K7AntiVirusTrojan ( 0058a7df1 )
AlibabaTrojan:Win32/runner.ali1000123
K7GWTrojan ( 0058a7df1 )
Cybereasonmalicious.5a2618
CyrenW32/Injector.APR.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Win32/Injector.EQOG
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Dropper.Win32.Nuldrop.gen
BitDefenderTrojan.GenericKD.38041556
AvastWin32:PWSX-gen [Trj]
Ad-AwareTrojan.GenericKD.38041556
SophosMal/Generic-S
ComodoTrojWare.Win32.UMal.mgame@0
DrWebTrojan.Siggen15.43265
TrendMicroTROJ_FRS.VSNTKH21
McAfee-GW-EditionRDN/Generic
EmsisoftTrojan.GenericKD.38041556 (B)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan-Stealer.FormBook.18GV21
WebrootW32.Injector.Gen
AviraTR/Injector.uyvzf
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/SpyNoon!MSR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4774723
McAfeeRDN/Generic
MAXmalware (ai score=84)
VBA32TrojanSpy.Noon
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTROJ_FRS.VSNTKH21
IkarusTrojan.Win32.Injector
FortinetW32/Injector.APR!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/SpyNoon!MSR?

Trojan:Win32/SpyNoon!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment