Malware

Mal/NafBot-A removal instruction

Malware Removal

The Mal/NafBot-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/NafBot-A virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Spanish (Mexican)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Mal/NafBot-A?


File Info:

name: 32D704E42CD5849E13EB.mlw
path: /opt/CAPEv2/storage/binaries/ad7073deafc4e2f51cc0a63093407e46ba104b3060e9ed68317bb25a7c722695
crc32: 86FBB5F9
md5: 32d704e42cd5849e13ebde6d2c25d954
sha1: b214be1ad8e2208a4dbdc9b0ad2e919a6c8a5785
sha256: ad7073deafc4e2f51cc0a63093407e46ba104b3060e9ed68317bb25a7c722695
sha512: 164c55771458615b09b6c0cf6d13d269a44dac977d14c9831a82104082009f2c6abe02fcd1f695a5bac726bfd19bfc526ad434a0250e5249be6c6664c19f7ae5
ssdeep: 1536:VZw6H61AOhqmY6zin5jn16YHGcARhkEbuWtF40xueuNTsYPl:VqeOhqmYNngNcATkEiWtFXu3BZl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13743F1C0F67EEC24DE61427017E7C52024E4E9A6EDF9E375C3C8E05A2D6A7E4985039B
sha3_384: fa4d6151e111f5e12d1a9a29b87950ab7abe353e80bda73576c52ef4adedc5eb6b627fec99f1b5997dd07d2a74f43882
ep_bytes: 60be00c042008dbe0050fdff5783cdff
timestamp: 2009-03-16 15:34:09

Version Info:

Comments:
CompanyName: Satinfo S.L.
FileDescription: Utilidad AntiVirus
FileVersion: 1, 8, 0, 0
InternalName: Elis
LegalCopyright: Copyright (C) 2009
LegalTrademarks:
OriginalFilename: Elis.EXE
PrivateBuild:
ProductName: Aplicación Elis
ProductVersion: 1, 8, 0, 0
SpecialBuild:
Translation: 0x0c0a 0x04b0

Mal/NafBot-A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MalwarebytesTrojan.Agent
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanDropper:Application/NafBot.cceb7a25
K7GWRiskware ( 00584baa1 )
Elasticmalicious (high confidence)
APEXMalicious
AvastWin32:Malware-gen
McAfee-GW-EditionBehavesLike.Win32.Dropper.qc
SophosMal/NafBot-A
IkarusTrojan-Dropper.Agent
Antiy-AVLTrojan/Win32.TSGeneric
XcitiumTrojWare.Win32.TrojanDownloader.IstBar.~L@f815z
GoogleDetected
McAfeeArtemis!32D704E42CD5
VBA32BScope.Trojan.DiskWriter
Cylanceunsafe
YandexTrojan.GenAsa!Sd+2aj1Bndk
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Mal/NafBot-A?

Mal/NafBot-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment