Backdoor

Backdoor.MSIL.NanoBot.benh removal instruction

Malware Removal

The Backdoor.MSIL.NanoBot.benh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.NanoBot.benh virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a hidden or system file
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
lookupnanor.mbplc.xyz

How to determine Backdoor.MSIL.NanoBot.benh?


File Info:

crc32: 2A9DC2A0
md5: eb3579b0ac81afac257ed6fabff0aab6
name: EB3579B0AC81AFAC257ED6FABFF0AAB6.mlw
sha1: 6100dfaf49b938ba09e0cb1267965eaf7ef8bfeb
sha256: d63175ae3ea02c89ea8c9e47bf9044f38ce0c8c2bf565a64d2f82eb37fbcdc6a
sha512: 830c370eaa96e5bab53aa53ec6f08e6f51f034440a34b3cd035c9cc24d1f9abbe0695dede6d9d646821ab33b7ceb0156787ebc7ac591a2a094b16fa3ae5a0764
ssdeep: 24576:5AOcZ6ZOcyasBKxYg923hwrfMY5aRcKXEeuT:zjAKxYL3hMU2aw1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.MSIL.NanoBot.benh also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Multi
ALYacTrojan.GenericKD.36987236
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f49b93
CyrenW32/Trojan.ODRX-0142
SymantecTrojan.Gen.2
ZonerTrojan.Win32.92739
APEXMalicious
AvastFileRepMalware
ClamAVWin.Dropper.Nanocore-9171337-0
KasperskyBackdoor.MSIL.NanoBot.benh
BitDefenderTrojan.GenericKD.37001483
ViRobotTrojan.Win32.Z.Agent.1129670
MicroWorld-eScanTrojan.GenericKD.37001483
Ad-AwareTrojan.GenericKD.37001483
SophosML/PE-A
ComodoTrojWare.Win32.UMal.qzpvd@0
TrendMicroTROJ_GEN.R002C0WEV21
McAfee-GW-EditionBehavesLike.Win32.Suspicioustrojan.tc
FireEyeGeneric.mg.eb3579b0ac81afac
EmsisoftTrojan.GenericKD.37001483 (B)
SentinelOneStatic AI – Suspicious SFX
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
GridinsoftRansom.Win32.Wacatac.oa!s1
AegisLabTrojan.Multi.Generic.4!c
GDataTrojan.GenericKD.37001483
AhnLab-V3Malware/Win32.RL_Generic.R362622
McAfeeArtemis!EB3579B0AC81
MAXmalware (ai score=99)
MalwarebytesTrojan.Dropper.SFX
RisingTrojan.Tiggre!8.ED98 (CLOUD)
IkarusTrojan-Spy.FormBook
AVGFileRepMalware

How to remove Backdoor.MSIL.NanoBot.benh?

Backdoor.MSIL.NanoBot.benh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment