Backdoor

Backdoor.MSIL.NanoBot.bbks (file analysis)

Malware Removal

The Backdoor.MSIL.NanoBot.bbks is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.NanoBot.bbks virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to mimic the file extension of a PDF document by having ‘pdf’ in the file name.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.MSIL.NanoBot.bbks?


File Info:

crc32: B72F2AF1
md5: 30826817cdb98d4306b4ce0e391b7bfd
name: 0392020_pdf.exe
sha1: 263b7d876faa498e88b9239d922225a2eae288c5
sha256: 5b1c2955557fd7891c6cf95c22439e662b94c4a4ec0eaadd70420a3fb347465c
sha512: c1e71777dc574108f46de940f8237c2d990413e15dac0fb4342ab75f389ce0824d37adf3828b6b9db281a62dd30d4afc2bbc24d6f4d8ef6e56da393a38cb9cfb
ssdeep: 768:lxLOV1oab9jRZ03v6zmMFcWEEozKxptTcbLvEFoGgkQInONXw47z4ZudzuRX8SP:l8IwjyfMFcWEEoGxp2vAMu4cnyx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: LAVENDE
InternalName: mundifycarti
FileVersion: 1.00
CompanyName: korrekthede
LegalTrademarks: DIPLOCARDIAC
Comments: efterlev
ProductName: PUNCHINELLOM
ProductVersion: 1.00
FileDescription: GTEPAGTSFORMU
OriginalFilename: mundifycarti.exe

Backdoor.MSIL.NanoBot.bbks also known as:

MicroWorld-eScanTrojan.GenericKD.33531900
Qihoo-360Generic/Backdoor.BO.1e5
McAfeeFareit-FRP!30826817CDB9
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005621711 )
BitDefenderTrojan.GenericKD.33531900
K7GWTrojan ( 005621711 )
Invinceaheuristic
F-ProtW32/Kryptik.BFV.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33531900
KasperskyBackdoor.MSIL.NanoBot.bbks
AlibabaTrojan:Win32/vbcrypt.ali2000008
AegisLabTrojan.MSIL.NanoBot.m!c
RisingBackdoor.NanoBot!8.28C (CLOUD)
EmsisoftTrojan.GenericKD.33531900 (B)
F-SecureTrojan.TR/Injector.vbiub
DrWebTrojan.DownLoader33.15484
TrendMicroTROJ_GEN.R011C0DCB20
McAfee-GW-EditionFareit-FRP!30826817CDB9
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.30826817cdb98d43
SophosMal/FareitVB-W
IkarusTrojan-Spy.Keylogger.AgentTesla
CyrenW32/Kryptik.BFV.gen!Eldorado
WebrootW32.Injector.Gen
AviraTR/Injector.vbiub
MAXmalware (ai score=99)
Antiy-AVLTrojan[Backdoor]/MSIL.NanoBot
MicrosoftTrojan:Win32/FormBook.AG!MTB
ArcabitTrojan.Generic.D1FFA7FC
ZoneAlarmBackdoor.MSIL.NanoBot.bbks
BitDefenderThetaGen:NN.ZevbaF.34100.fm0@aCdOfrdi
ALYacTrojan.GenericKD.33531900
VBA32BScope.Trojan.Sonbokli
MalwarebytesTrojan.GuLoader
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EKYU
TrendMicro-HouseCallTROJ_GEN.R011C0DCB20
TencentMsil.Backdoor.Nanobot.Lhws
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ELAK!tr
Ad-AwareTrojan.GenericKD.33531900
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Backdoor.MSIL.NanoBot.bbks?

Backdoor.MSIL.NanoBot.bbks removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment