Backdoor

How to remove “Backdoor.RAT.MSIL.NanoCore”?

Malware Removal

The Backdoor.RAT.MSIL.NanoCore is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.RAT.MSIL.NanoCore virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Backdoor.RAT.MSIL.NanoCore?


File Info:

crc32: E6C5F3AA
md5: 30824ad9a5e6e351d9d55a369b5bded4
name: nass.exe
sha1: e436d906451d7aa3f99889b2b39775590262ed53
sha256: 1306a3b44cf529bbb9b344165a170535bd92d276cbbba07d0fccfcce485ca781
sha512: a1e9bb7bf85d1411fdf7729b58e652bfebf36e00d5e9d5764ce6cc531a8ef9f80a4854bfa15677b677855e7a0ff294045ebbcd80f4834bfa7a08c8b0ac38246c
ssdeep: 12288:TEBJRb2M8IQahdI1xxKkHzcVf9/iB8gw1Jq+u7pJqiFIHim47wuIdn9m+lPdyNs:ulkIrVJ5
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Backdoor.RAT.MSIL.NanoCore also known as:

MicroWorld-eScanTrojan.GenericKD.42081186
FireEyeTrojan.GenericKD.42081186
CAT-QuickHealTrojan.MSIL
ALYacBackdoor.RAT.MSIL.NanoCore
MalwarebytesTrojan.RCrypt.MSIL.Generic
SangforMalware
K7AntiVirusTrojan ( 0055c4231 )
BitDefenderTrojan.GenericKD.42081186
K7GWTrojan ( 0055c4231 )
TrendMicroTROJ_GEN.R002C0TL319
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.42081186
KasperskyHEUR:Trojan.MSIL.DOTHETUK.gen
AlibabaTrojan:MSIL/Kryptik.c9715576
NANO-AntivirusTrojan.Win32.Kryptik.gkovzh
AegisLabTrojan.Win32.Generic.4!c
AvastWin32:RATX-gen [Trj]
Ad-AwareTrojan.GenericKD.42081186
EmsisoftTrojan.GenericKD.42081186 (B)
ComodoMalware@#2i035hzs8r48z
F-SecureTrojan.TR/AD.Sagonaire.onkgl
DrWebTrojan.Siggen8.59892
ZillyaTrojan.Kryptik.Win32.1870558
McAfee-GW-EditionBehavesLike.Win32.PUPXBZ.jt
SophosMal/Generic-S
IkarusTrojan.MSIL.Inject
CyrenW32/MSIL_Kryptik.ZQ.gen!Eldorado
WebrootW32.Trojan.Gen
AviraTR/AD.Sagonaire.onkgl
MAXmalware (ai score=100)
Antiy-AVLTrojan/MSIL.DOTHETUK
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2821BA2
ZoneAlarmHEUR:Trojan.MSIL.DOTHETUK.gen
MicrosoftTrojan:MSIL/NanoCore.TVW!MTB
AhnLab-V3Malware/Win32.RL_Generic.C3606619
Acronissuspicious
McAfeeGenericRXJG-EH!30824AD9A5E6
VBA32TScope.Trojan.MSIL
CylanceUnsafe
ESET-NOD32a variant of MSIL/Kryptik.TVW
TrendMicro-HouseCallTROJ_GEN.R002C0TL319
FortinetMSIL/Kryptik.TVW!tr
BitDefenderThetaGen:NN.ZemsilF.32519.QmW@amAjl2mi
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360HEUR/QVM03.0.A19D.Malware.Gen

How to remove Backdoor.RAT.MSIL.NanoCore?

Backdoor.RAT.MSIL.NanoCore removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment