Backdoor

About “Backdoor.MSIL.NanoBot.nqs” infection

Malware Removal

The Backdoor.MSIL.NanoBot.nqs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.NanoBot.nqs virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine Backdoor.MSIL.NanoBot.nqs?


File Info:

name: 4D7B22C8FE035E077B97.mlw
path: /opt/CAPEv2/storage/binaries/261d471ebc828ce01cccb2ee7c2e24ae599cf2f71ff39a966b49b66fb7ca39e3
crc32: 8432FE05
md5: 4d7b22c8fe035e077b97ef1e916a9907
sha1: 7da5bbfd3b047b8a06ec97ae46b466851836dee1
sha256: 261d471ebc828ce01cccb2ee7c2e24ae599cf2f71ff39a966b49b66fb7ca39e3
sha512: e0d43800ee5e3b3d8430b672a1b116c1aede1eb89cf46071b27802ea547a47ef03e68031fcfb84f6177014252b17264a714f0e400ab5ddfe5774deb014ffa27d
ssdeep: 196608:M1b6wNLtXj8DKwf9lK6PH5Dxo4Y7weM8uAsVu/RcU1mjKLNXZ:M1b6mtXj8Kwf/K6BD2d7+j1upcMr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AF9633A5B6065CD0DB89463517A43EE0AC824F8F77BA5C0FFD71CAA2447B68AC7441B3
sha3_384: 1232eaec0dec2fec95d9887fa1fcedf9df7e939d5ddbea6dd9b8b1f5d481002fcd65c1776bec8ec959a9d6041ce1ce32
ep_bytes: 81ec800100005355565733db68018000
timestamp: 2015-12-27 05:38:55

Version Info:

0: [No Data]

Backdoor.MSIL.NanoBot.nqs also known as:

DrWebTrojan.Nanocore.23
MicroWorld-eScanDropped:Trojan.Autoruns.GenericKD.41447611
FireEyeGeneric.mg.4d7b22c8fe035e07
CAT-QuickHealBackdoor.Noancooe
ALYacDropped:Trojan.Autoruns.GenericKD.41447611
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0056397b1 )
AlibabaBackdoor:MSIL/NanoBot.7479ff49
K7GWTrojan ( 0056397b1 )
Cybereasonmalicious.8fe035
BitDefenderThetaGen:NN.ZemsilF.34182.Zq0@ayu6wUm
CyrenW32/Trojan.TDXK-1098
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Score-6915874-0
KasperskyBackdoor.MSIL.NanoBot.nqs
BitDefenderDropped:Trojan.Autoruns.GenericKD.41447611
NANO-AntivirusTrojan.Win32.NanoBot.egqlol
AvastWin32:Malware-gen
TencentMsil.Backdoor.Nanobot.Pfjv
SophosMal/Generic-S
ComodoMalware@#1li4si5a11n76
TrendMicroTROJ_GEN.R002C0GJE21
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
EmsisoftDropped:Trojan.Autoruns.GenericKD.41447611 (B)
IkarusTrojan.MSIL.NanoCore
JiangminTrojan.MSIL.aoth
AviraHEUR/AGEN.1112142
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.1B76190
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ViRobotTrojan.Win32.Z.Nanocore.9018189
ZoneAlarmBackdoor.MSIL.NanoBot.nqs
GDataDropped:Trojan.Autoruns.GenericKD.41447611
CynetMalicious (score: 99)
AhnLab-V3Backdoor/Win32.NanoBot.C4280627
McAfeeArtemis!4D7B22C8FE03
VBA32Backdoor.MSIL.NanoBot
MalwarebytesMalware.AI.546129963
TrendMicro-HouseCallTROJ_GEN.R002C0GJE21
RisingTrojan.Generic/MSIL@AI.93 (RDM.MSIL:VgmHmHWH07Ghv2F8bOl/Ag)
YandexTrojan.Agent!nrilvUDVlvk
FortinetMSIL/Generic.DN.45C4C3!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.MSIL.NanoBot.nqs?

Backdoor.MSIL.NanoBot.nqs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment