Threat Database Trojans Trojan.Nooby.A

Trojan.Nooby.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 21,044
Threat Level: 80 % (High)
Infected Computers: 633
First Seen: January 19, 2011
Last Seen: August 25, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Nooby.A
Signature status: No Signature

Known Samples

MD5: b42042c921bca8b012ee0c152659668b
SHA1: 51bb040aa7826f65d76a7d966c2565c20e5e4375
SHA256: 62DB5C0FC1B3ECA8869E992B1AF25B3776A166EFA21099508DCE8B4011AA36DA
File Size: 2.54 MB, 2540544 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description CarSoftware
File Version 1.0.0.0
Internal Name CarSoftware.exe
Legal Copyright Copyright © 2008
Original Filename CarSoftware.exe
Product Name CarSoftware
Product Version 1.0.0.0

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 2,159
Potentially Malicious Blocks: 1,663
Whitelisted Blocks: 478
Unknown Blocks: 18

Visual Map

x 0 x x x x x x x x x x x x x x 0 0 x x 0 x x x x x x x 0 x x x x x x x 0 x x x x x x 0 x x x x x x 0 0 x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x 0 x x 0 x x 0 x x x x x x x 0 x x x x x x x x 0 x x x x x 0 x x 0 x x x x x x 0 x x x x x x x x x x 0 0 x x x x x x x 0 x 0 x x 0 x 0 0 x x x 0 x x x x 0 x x x x x x x x x x x x 0 x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x 0 x 0 0 0 x x x x x x x x x x x 0 x 0 0 x x x 0 0 0 x x 0 0 x x 0 x x x 0 x 0 0 x 0 0 0 x x x x 0 x x 0 0 x x x 0 x 0 0 x x 0 x 0 x x x x x x 0 0 x 0 x 0 x 0 x x x x x x x x 0 0 x x 0 x x x 0 0 x x 0 x x x 0 0 0 x x x x x 0 x x 0 x x x x 0 0 0 x x x x x x x x 0 x 0 x 0 x x x 0 x 0 x x x x x 0 x x x x 0 x x 0 x x x x x x x x x x 0 x 0 x x x x x x x x 0 x 0 x x x x x 0 x x x x 0 0 x x x x x x x x 0 x x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x 0 x x x 0 x 0 x x x x x x x x x x x x x x x 0 0 x 0 x x 0 x 0 x x 0 x x x x 0 x x x x x 0 0 x 0 x x x x x x x x x x x 0 0 x x x x x x x x 0 x x 0 x x 0 x x x x x x x x x 0 x x x 0 x x 0 0 0 x x x x x x x 0 x x 0 x x x 0 x x x x x x x x x x x x 0 x x x x 0 x x x x x x x x x x 0 0 x 0 x x x 0 x x x x x 0 x 0 0 x x 0 x 0 0 x 0 0 x x x x x x x x 0 0 0 x x x 0 x x 0 x 0 x x x 0 x x x x x x 0 x x x x 0 x x x 0 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x 0 0 x 0 x x x x x x x 0 0 x x x x x 0 x x x x x x x x 0 0 0 x x x x x x x x x x x x x x x x 0 0 x x x x x 0 x x x x x 0 0 x x x x x x x x x x 0 x 0 x x x 0 0 0 0 x 0 x x 0 x x 0 x x 0 0 x 0 x 0 x x x 0 x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x x 0 x x 0 x x x x 0 x x 0 x x x 0 x x x 0 x 0 x 0 0 x x x x x 0 x x 0 x x 0 x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 0 x x x x 0 x x x x x x x x x x x x x x x x 0 x x x 0 0 0 x x x x x 0 x x 0 x x x x 0 x x 0 x x 0 x x x x x x 0 x 0 x x x x x x 0 x x x x 0 x 0 x 0 x x x x x x 0 x x x 0 x x x x x x 0 x 0 0 x 0 0 x x x 0 x x x 0 x x x x x 0 x x x x x x x 0 0 x 0 x 0 x 0 x x x 0 x x x x 0 0 x x x 0 x 0 x x x x x x 0 x x x x 0 x x x 0 x x 0 0 x 0 0 0 x x x x x x x x x x 0 x 0 0 0 x 0 x x x x 0 0 0 0 x x x x x x x x 0 0 x x x x x x 0 x x 0 0 x x x 0 0 0 x x 0 x 0 x x x x x 0 x x x x 0 x x x 0 x x x x x x x x x x 0 x x x x x x x x x x x x x 0 x x x x x x x x x x 0 x x x 0 x x x x x 0 x x x 0 x x 0 x x x x x 0 x x x x x x 0 x x x 0 0 x x x 0 0 0 x x 0 x x x x 0 0 0 x x x x 0 x x 0 x x x x x 0 0 x 0 x x x x x x x x x x x x x x x x 0 x x x x x x x x x x 0 x x x 0 x x x x x x 0 x 0 x x x x 0 x x 0 x 0 x x x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x x x x 0 0 x 0 x x 0 x x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x 0 x x x x x x x x x x 0 x x x x x x x x x x x 0 x x 0 x x x x x x x x x x x x x x 0 x 0 x 0 x x x 0 x x 0 x x 0 0 x x x x x x 0 0 x x x 0 x x x x x x x 0 x 0 x x x x x x 0 x x x x x x 0 0 x x 0 x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 0 0 x 0 x x x x x x 0 x 0 x 0 x x x x x x x x 0 x 0 x x x x 0 x 0 x 0 x x 0 x 0 x x x 0 x x x x x x x x x x x 0 x 0 0 x 0 x x x x 0 x x x x x x x x x 0 0 x x x x x x 0 0 0 x x x 0 0 x x 0 0 x x x x x x x x x x x x x x 0 x x x x x x x x x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x 0 x x x x x 0 x x 0 x x x x x x x 0 x x 0 x x x x x x 0 x x x 0 0 0 x x x 0 x x 0 0 x x x x 0 x x 0 x x x x x x x x x x x 0 x x x x x x 0 x x x 0 x 0 x 0 x x x x x x x x x 0 x x 0 x x x x x x x x x x x x x x x x x 0 x x x x x x 0 x x x 0 x 0 x x x x 0 x x x x x x x 0 x x x x 0 x 0 x 0 x 0 0 x 0 x 0 0 x x x x x x x x x x x x x x 0 0 x x 0 x x x x 0 x x x x x x 0 0 0 x x 0 x 0 x x x x x 0 x x x x 0 0 x x 0 x x 0 x x x x x x x x 0 x 0 x 0 x x 0 x 0 0 x 0 0 x x x 0 x x x x x 0 x x x x x x x x 0 0 0 x x 0 x x x x 0 x x x x x x x x 0 x x x x x x x x x x 0 x x x 0 x x x x x x x x x 0 x 0 0 x x x x x 0 0 x 0 x 0 x 0 x x x x 0 x x 0 x x x x x x x 0 x x 0 x x 0 x x x x x x 0 x x x 0 x x 0 x x x x x 0 0 x x x 0 x x x x x 0 0 x 0 x 0 x x x x x x x 0 x x x x x x 0 x x 0 x 0 x x x x x x x x x 0 x x x 0 x 0 0 x x 0 0 0 x 0 x x 0 0 x x x 0 x x x x x x x x x 0 x x 0 x x x x x x x x 0 0 0 0 x x x x x x x x 0 x 0 x x x 0 0 x x x 0 x 0 0 x x 0 0 x x x 0 x x 0 x x x x x x x x ? ? x x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Nooby.A

Files Modified

File Attributes
c:\windows\system.ini Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\advanced::hidden  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusoverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalldisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalloverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::updatesdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::uacdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::antivirusoverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::antivirusdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::firewalldisablenotify  RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\security center\svc::firewalloverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::updatesdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::uacdisablenotify  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings::globaluseroffline RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\system::enablelua RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::enablefirewall RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::donotallowexceptions RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::disablenotifications  RegNtPreCreateKey
HKCU\software\apcr\1214104697::1919251317 RegNtPreCreateKey
HKCU\software\apcr\1214104697::-456464662 RegNtPreCreateKey
HKCU\software\apcr\1214104697::1462786655 RegNtPreCreateKey
HKCU\software\apcr\1214104697::-912929324 # RegNtPreCreateKey
HKCU\software\apcr\1214104697::1006321993 Ĝ RegNtPreCreateKey
HKCU\software\apcr\1214104697::-1369393986 http://theunforgiven.p8.hu/img/top.gifhttp://painelwebradiodi RegNtPreCreateKey
HKCU\software\apcr\1214104697::549857331 5��8eM{��(.��I��#����D�E;O�{�a�� ��`��2f�ha/��A�:'���+ RegNtPreCreateKey