Malware

What is “Perl/Shellbot.NAK”?

Malware Removal

The Perl/Shellbot.NAK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Perl/Shellbot.NAK virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

How to determine Perl/Shellbot.NAK?


File Info:

crc32: 75FF3EB1
md5: 4644c123c994744f4042222a22f1b33f
name: tmp_rqi2ha4
sha1: e861fc02b451e223ec042b35904c7fd3472f100e
sha256: e7deaa42c57249a7a925b31c9e5f9d18073556906bf930d178c30b76ee4aea63
sha512: 64cf5fd992ab8fb5d057c4937a59e6ac880ef0f4663ec2814fdcf5018f4d0f4d623b7b5b8f134058227f56f39b2e43267cc06cb414fa2e6f75256b7a22ac68c6
ssdeep: 768:73UgGAAMROJ3KbZcUMoEGZYFu+tVwU1LKCoEKh:7M/MNEtVwU1LgEKh
type: Perl script, ASCII text executable, with very long lines

Version Info:

0: [No Data]

Perl/Shellbot.NAK also known as:

ALYacTrojan.GenericKD.43222831
ArcabitTrojan.Generic.D293872F
ESET-NOD32Perl/Shellbot.NAK
KasperskyHEUR:Trojan-Downloader.Shell.Agent.e
BitDefenderTrojan.GenericKD.43222831
MicroWorld-eScanTrojan.GenericKD.43222831
RisingTrojan.Shellbot!8.618 (TOPIS:E0:rAUFcqxEzCB)
Ad-AwareTrojan.GenericKD.43222831
EmsisoftTrojan.GenericKD.43222831 (B)
FireEyeTrojan.GenericKD.43222831
AegisLabTrojan.Shell.Agent.a!c
ZoneAlarmHEUR:Trojan-Downloader.Shell.Agent.e
MAXmalware (ai score=89)
GDataTrojan.GenericKD.43222831
Qihoo-360Generic/Trojan.Downloader.2f2

How to remove Perl/Shellbot.NAK?

Perl/Shellbot.NAK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment