Categories: Backdoor

Backdoor:MSIL/NanoBot.RKC!MTB removal guide

The Backdoor:MSIL/NanoBot.RKC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/NanoBot.RKC!MTB virus can do?

  • Network activity detected but not expressed in API logs

How to determine Backdoor:MSIL/NanoBot.RKC!MTB?


File Info:

crc32: ADBA3892md5: 32d902404889e352b0ee10182c737a69name: 32D902404889E352B0EE10182C737A69.mlwsha1: b2726a921dcc1837e897944c6ce2492084e764f0sha256: 2dce266f65b63c927ddf95e71bb0d226eb1c8b260ba8a6965ba1352e9fa837afsha512: 8bc25083e64541932b4e5d5411604e8b19b80b668ceafe1fc641853be748450a71a7a11dbba81571651ca8a32caa5b9ba5c57a2a92165e8fe9d34a31874e68c7ssdeep: 12288:FhZd8fWJWprrDlkJaWBDn5MBK92+bPGv2iD/EadhH:GWEpr1kJzmBM2+KTE+htype: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0LegalCopyright: Copyright xa9 2013Assembly Version: 1.0.0.0InternalName: DependentOSMetadataEntryFieldId.exeFileVersion: 1.0.0.0CompanyName: LegalTrademarks: Comments: ProductName: StageOpvolgingProductVersion: 1.0.0.0FileDescription: StageOpvolgingOriginalFilename: DependentOSMetadataEntryFieldId.exe

Backdoor:MSIL/NanoBot.RKC!MTB also known as:

Elastic malicious (high confidence)
DrWeb Trojan.PackedNET.539
MicroWorld-eScan Trojan.GenericKD.36322494
ALYac Trojan.GenericKD.36322494
Sangfor Backdoor.MSIL.Remcos.gen
K7AntiVirus Trojan ( 005779c81 )
BitDefender Trojan.GenericKD.36322494
K7GW Trojan ( 005779c81 )
BitDefenderTheta Gen:NN.ZemsilF.34804.2m0@ai73IKo
Cyren W32/MSIL_Kryptik.CYQ.gen!Eldorado
Symantec Trojan.Gen.2
APEX Malicious
Avast Win32:RATX-gen [Trj]
Kaspersky HEUR:Backdoor.MSIL.Remcos.gen
Alibaba Backdoor:MSIL/Kryptik.b2b586f7
AegisLab Trojan.Win32.Malicious.4!c
Rising Backdoor.Remcos!8.B89E (CLOUD)
Ad-Aware Trojan.GenericKD.36322494
Emsisoft Trojan.GenericKD.36322494 (B)
Comodo Malware@#lkv8ki67ec07
TrendMicro Backdoor.MSIL.REMCOS.USMANEAGIG
McAfee-GW-Edition BehavesLike.Win32.Generic.ch
FireEye Generic.mg.32d902404889e352
Sophos Mal/Generic-S + Troj/Kryptik-SM
Ikarus Trojan.Inject
Kingsoft Win32.Hack.Undef.(kcloud)
Microsoft Backdoor:MSIL/NanoBot.RKC!MTB
Gridinsoft Trojan.Win32.Kryptik.oa
Arcabit Trojan.Generic.D22A3CBE
ZoneAlarm HEUR:Backdoor.MSIL.Remcos.gen
GData Trojan.GenericKD.36322494
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Gen.RL_Reputation.C4331107
McAfee RDN/Generic.dx
MAX malware (ai score=99)
Malwarebytes Spyware.AgentTesla
Panda Trj/GdSda.A
Zoner Trojan.Win32.104327
ESET-NOD32 a variant of MSIL/Kryptik.ZPV
TrendMicro-HouseCall Backdoor.MSIL.REMCOS.USMANEAGIG
Tencent Win32.Trojan.Inject.Auto
Yandex Trojan.AvsArher.bUSH7p
SentinelOne Static AI – Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.ZOD!tr
Webroot W32.Trojan.Gen
AVG Win32:RATX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_60% (W)
Qihoo-360 Win32/Trojan.Generic.HwMALsQA

How to remove Backdoor:MSIL/NanoBot.RKC!MTB?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Trojan:Win32/LummaStealer.CADV!MTB removal guide

The Trojan:Win32/LummaStealer.CADV!MTB is considered dangerous by lots of security experts. When this infection is active,…

13 mins ago

MSILHeracles.99188 removal instruction

The MSILHeracles.99188 is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago

Trojan:MSIL/AgentTesla.NEC!MTB removal tips

The Trojan:MSIL/AgentTesla.NEC!MTB is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago

Malware.AI.4168650666 removal instruction

The Malware.AI.4168650666 is considered dangerous by lots of security experts. When this infection is active,…

40 mins ago

About “Malware.AI.4026059104” infection

The Malware.AI.4026059104 is considered dangerous by lots of security experts. When this infection is active,…

48 mins ago

IL:Trojan.MSILZilla.120623 information

The IL:Trojan.MSILZilla.120623 is considered dangerous by lots of security experts. When this infection is active,…

49 mins ago