Backdoor

Should I remove “Backdoor.MSIL.NanoBot.ayae”?

Malware Removal

The Backdoor.MSIL.NanoBot.ayae is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.NanoBot.ayae virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.MSIL.NanoBot.ayae?


File Info:

crc32: 734CA8A4
md5: db634e6548ff85b797a2f430909d235f
name: valid.jpg
sha1: 347798f5fd34b3f9a5c285c1369c72e6ca0ac6fe
sha256: bc7c6248284b34052cfc1b33fe87e44f777cf5b64e7be218d2b2fc6c61eb3f13
sha512: d0b2b9cdca4ad97d1416a8777bde78fbbc91a44dacc02b14e028580c2ab8d0dcae653154ed58bd988e3ecf8d7c82be75c9ed9e5d03f6a16a541fe4d148d92ce4
ssdeep: 12288:87dAJRUvRmjfGGEld9So+0QOHpmc//7j9H5xtGG0yQEnnnn:6iJRUZmjfGGElmo+0R9HL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: TRAtta
FileVersion: 1.04.0005
CompanyName: Gsuo
ProductName: TRYGehesO
ProductVersion: 1.04.0005
OriginalFilename: TRAtta.exe

Backdoor.MSIL.NanoBot.ayae also known as:

MicroWorld-eScanTrojan.GenericKD.32728389
ALYacTrojan.GenericKD.32728389
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.NanoBot.m!c
SangforMalware
K7AntiVirusTrojan ( 0055bb411 )
BitDefenderTrojan.GenericKD.32728389
K7GWTrojan ( 0055bb411 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_FRS.VSNW13K19
BitDefenderThetaGen:NN.ZevbaF.32517.Em0@aa7v@bmi
F-ProtW32/VBKrypt.ACI.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_FRS.VSNW13K19
AvastWin32:CrypterX-gen [Trj]
GDataTrojan.GenericKD.32728389
KasperskyBackdoor.MSIL.NanoBot.ayae
NANO-AntivirusTrojan.Win32.NanoBot.gixxuf
Ad-AwareTrojan.GenericKD.32728389
SophosMal/FareitVB-X
ComodoMalware@#3k6cb5ytgg36h
F-SecureTrojan.TR/Injector.updwz
DrWebTrojan.DownLoader30.43003
Invinceaheuristic
McAfee-GW-EditionFareit-FQK!DB634E6548FF
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.db634e6548ff85b7
APEXMalicious
CyrenW32/VBKrypt.ABX.gen!Eldorado
JiangminBackdoor.MSIL.ceuw
WebrootW32.Trojan.GenKD
AviraTR/Injector.updwz
MAXmalware (ai score=85)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F36545
ZoneAlarmBackdoor.MSIL.NanoBot.ayae
MicrosoftTrojan:Win32/Occamy.C
SentinelOneDFI – Malicious PE
AhnLab-V3Trojan/Win32.Injector.C3576948
McAfeeFareit-FQK!DB634E6548FF
TACHYONBackdoor/W32.VB-NanoBot.495616.C
PandaGeneric Malware
ESET-NOD32a variant of Win32/Injector.EIZE
YandexBackdoor.NanoBot!
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.74701188.susgen
FortinetW32/Injector.DXWP!tr
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.5fd34b
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.BO.281

How to remove Backdoor.MSIL.NanoBot.ayae?

Backdoor.MSIL.NanoBot.ayae removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment