Malware

Win32/NoonLight.Z malicious file

Malware Removal

The Win32/NoonLight.Z is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/NoonLight.Z virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Win32/NoonLight.Z?


File Info:

name: 111D1BE381E58805800E.mlw
path: /opt/CAPEv2/storage/binaries/e0f8c0dddb78e068f9b801e78bf6684897c342eeab6066f036dc825e15b13398
crc32: 2D13CA65
md5: 111d1be381e58805800e5d3241bf35d2
sha1: 8811995363ff09afb75856b16cc8643e4faf28fc
sha256: e0f8c0dddb78e068f9b801e78bf6684897c342eeab6066f036dc825e15b13398
sha512: 833b183e8b398472625ebce978915ffcff9aeffc358e01ceb54252d888f80be7e77455c17552c470e40accb4b638431737a962dba3bd925221b459ce55bb7ce8
ssdeep: 3072:2eH4sa2QD7MRWrUBluGjvocpd6iPminKSdEjBDJRWci+O:2Y+32WWluqvHpVmXWEjFJRWci+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T167D3D417FB517129F263847A7838922AA4293D350A01AC5BF3826F5A34716D3F9F172F
sha3_384: 765650c2a831e654db9fae3ddc9ef83113c1b54a2b3ae9517a33d3d8aeffe004c930ea525137558c0ece2b6f008d7554
ep_bytes: e9560b00000058055a0b00008b3003f0
timestamp: 2007-01-12 10:04:58

Version Info:

Translation: 0x0409 0x04b0
Comments: Microsoft Corporation
CompanyName: File Folder
ProductName:
FileVersion: 1.00
ProductVersion: 1.00
InternalName: FILE FOLDER
OriginalFilename: FILE FOLDER.exe

Win32/NoonLight.Z also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.im0@rPGDtMcib
FireEyeGeneric.mg.111d1be381e58805
ALYacGen:Trojan.Heur.im0@rPGDtMcib
CylanceUnsafe
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_70% (D)
ArcabitTrojan.Heur.EC07B9
BitDefenderThetaAI:Packer.9B833ED41D
CyrenW32/Backdoor.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/NoonLight.Z
BaiduWin32.Worm.VB.a
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Email-Worm.Win32.Convagent.gen
BitDefenderGen:Trojan.Heur.im0@rPGDtMcib
AvastWin32:VB-DHR [Wrm]
Ad-AwareGen:Trojan.Heur.im0@rPGDtMcib
EmsisoftGen:Trojan.Heur.im0@rPGDtMcib (B)
ComodoTrojWare.Win32.Trojan.VB.~C@mmmg2
F-SecureTrojan.TR/Crypt.CFI.Gen
DrWebTrojan.DownLoader6.64360
VIPREGen:Trojan.Heur.im0@rPGDtMcib
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Refroso.afgk
AviraTR/Crypt.CFI.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmVHO:Email-Worm.Win32.Convagent.gen
GDataGen:Trojan.Heur.im0@rPGDtMcib
GoogleDetected
AhnLab-V3Worm/Win.VB.R526135
McAfeeGenericRXAA-FA!111D1BE381E5
MAXmalware (ai score=81)
RisingWorm.VBInjectEx!1.99E6 (CLASSIC)
IkarusTrojan.Win32.Patched
AVGWin32:VB-DHR [Wrm]

How to remove Win32/NoonLight.Z?

Win32/NoonLight.Z removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment