Malware

ML/PE-A + Troj/NanoCor-BT removal guide

Malware Removal

The ML/PE-A + Troj/NanoCor-BT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/NanoCor-BT virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine ML/PE-A + Troj/NanoCor-BT?


File Info:

crc32: A1D4E767
md5: 8795d3bbc6af647874cc317eab8854ce
name: 8795D3BBC6AF647874CC317EAB8854CE.mlw
sha1: 7a43b3d4ae9ee39a7f55ab75861ab1bf391db261
sha256: 101e4e7d2869d80986ec3e2f0ff6cbf2d5b3ae68f4b34423149ec2892df5d265
sha512: 6bfea8c47d353db6629f646e93a493a8bf56d71b63d72b464385bd04b1a2e6a4aa1d5bc7cb74f1bef3597d80d7063d507507c1440e21db147306143a20e278fd
ssdeep: 6144:sLV6Bta6dtJmakIM5cc0kTgdXi6Wv7zoEh:sLV6BtpmkXc1cXNYAw
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

ML/PE-A + Troj/NanoCor-BT also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Nanocore.23
MicroWorld-eScanBackdoor.MSIL.Agent.GD
CAT-QuickHealTrojan.Orbus.C3
Qihoo-360HEUR/QVM03.0.85D9.Malware.Gen
ALYacBackdoor.MSIL.Agent.GD
CylanceUnsafe
VIPRETrojan.MSIL.NanoCore.B (fs)
K7AntiVirusTrojan ( 700000121 )
BitDefenderBackdoor.MSIL.Agent.GD
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZemsilF.34658.mmW@aWHpUbp
CyrenW32/NanoCore.C.gen!Eldorado
SymantecTrojan.Nancrat
APEXMalicious
AvastMSIL:NanoCore-B [Trj]
ClamAVWin.Trojan.Nanocore-5
KasperskyTrojan.MSIL.Agent.fpar
NANO-AntivirusTrojan.Win32.NanoBot.hmqoyu
ViRobotBackdoor.Win32.NanoCore.Gen.A
RisingBackdoor.NanoCore!1.B6F9 (CLASSIC)
Ad-AwareBackdoor.MSIL.Agent.GD
TACHYONBackdoor/W32.DN-Nanocore.207872
EmsisoftTrojan.NanoCore (A)
ComodoBackdoor.MSIL.Noancooe.JDE@5s4u9t
F-SecureTrojan.TR/Dropper.MSIL.Gen7
TrendMicroBKDR_NOANCOOE.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.8795d3bbc6af6478
SophosML/PE-A + Troj/NanoCor-BT
IkarusBackdoor.Rat.Nanocore
JiangminBackdoor.Generic.zwu
WebrootW32.Trojan.MSIL.NanoCore
AviraTR/Dropper.MSIL.Gen7
MicrosoftBackdoor:MSIL/Nanocore.S!MTB
GridinsoftBackdoor.Win32.Noancooe.cc!ni
ArcabitBackdoor.MSIL.Agent.GD
SUPERAntiSpywareBackdoor.Nanocore/Variant
ZoneAlarmTrojan.MSIL.Agent.fpar
GDataMSIL.Backdoor.Nancat.A
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Nanocore.Exp
Acronissuspicious
McAfeeTrojan-FICC!8795D3BBC6AF
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.NanoCore
PandaBck/Agent.KNM
ZonerTrojan.Win32.48280
ESET-NOD32MSIL/NanoCore.E
TrendMicro-HouseCallBKDR_NOANCOOE.SM
TencentMsil.Trojan.Agent.Ebqr
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
FortinetW32/Generic.AC.A0C!tr
AVGMSIL:NanoCore-B [Trj]
MaxSecureTrojan.Malware.300983.susgen

How to remove ML/PE-A + Troj/NanoCor-BT?

ML/PE-A + Troj/NanoCor-BT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment