Backdoor

Backdoor:MSIL/Nanocore!MTB information

Malware Removal

The Backdoor:MSIL/Nanocore!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/Nanocore!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Backdoor:MSIL/Nanocore!MTB?


File Info:

crc32: 379F7C50
md5: fe3fe5aac1ef82533bc91114f13b126f
name: vv.exe
sha1: cc7c99b18bfa144bcbed6924cfab38eb5930f192
sha256: 9af617aca1a8bc563a159b62823bdbe8ee14f4731e1a0a979b3a421be3b91882
sha512: a1955f77e156318a7e4cb7f541bdf13fb2f203e8c0c51f096748379154444b5b27590748940a93edf45cb7fd8067b39c932e7c9050a626237829dc453bb680b2
ssdeep: 24576:MMnuevKcylapA7GtgaoZrpNImLjbZtgntXIEnWqn9W+oRyqfdR:ln/w1XiUB
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Backdoor:MSIL/Nanocore!MTB also known as:

MicroWorld-eScanGen:Variant.Razy.549478
FireEyeGeneric.mg.fe3fe5aac1ef8253
CAT-QuickHealTrojan.MsilFC.S8705609
Qihoo-360Win32/Trojan.21a
McAfeeTrojan-FRIK!FE3FE5AAC1EF
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1752267
AegisLabTrojan.MSIL.Crypt.4!c
SangforMalware
K7AntiVirusTrojan ( 0055d98d1 )
BitDefenderGen:Variant.Razy.549478
K7GWTrojan ( 0055d98d1 )
Invinceaheuristic
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Razy.549478
KasperskyHEUR:Trojan.MSIL.Crypt.gen
AlibabaBackdoor:MSIL/Nanocore.c4ccd16e
NANO-AntivirusTrojan.Win32.Crypt.fzuvdl
RisingBackdoor.Nanocore!8.F894 (CLOUD)
Ad-AwareGen:Variant.Razy.549478
EmsisoftGen:Variant.Razy.549478 (B)
F-SecureTrojan.TR/Kryptik.cxiun
DrWebTrojan.PWS.Siggen2.28957
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.MSIL.NANOCORE.SMQ.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosMal/Generic-S
IkarusTrojan.MSIL.Inject
CyrenW32/MSIL_Kryptik.OH.gen!Eldorado
JiangminTrojan.MSIL.mmxn
WebrootW32.Trojan.Gen
AviraTR/Kryptik.cxiun
MAXmalware (ai score=100)
Antiy-AVLTrojan/MSIL.Crypt
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D86266
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
MicrosoftBackdoor:MSIL/Nanocore!MTB
AhnLab-V3Malware/Win32.RL_Generic.C3447502
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34090.inW@aSdGHhEi
ALYacGen:Variant.Razy.549478
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.HCrypt.Generic
PandaTrj/CI.A
ZonerTrojan.Win32.80748
ESET-NOD32a variant of MSIL/Kryptik.SQK
TrendMicro-HouseCallTrojanSpy.MSIL.NANOCORE.SMQ.hp
TencentMsil.Trojan.Crypt.Eerf
YandexTrojan.Crypt!0QkTTEwOEWM
eGambitUnsafe.AI_Score_98%
FortinetMSIL/GenKryptik.DQPR!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.11716371.susgen

How to remove Backdoor:MSIL/Nanocore!MTB?

Backdoor:MSIL/Nanocore!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment