Trojan

Trojan.Nanocore.S15454114 removal guide

Malware Removal

The Trojan.Nanocore.S15454114 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Nanocore.S15454114 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Trojan.Nanocore.S15454114?


File Info:

crc32: 12FF4BE6
md5: 1c619b1dc7a9ed8e574262a1575631fc
name: Ref ____ No. 13082020 ___ Scan.exe
sha1: 49e5090c39783e04584f7723b461c5399daaea5a
sha256: 7c6da3c6cdc2c4ba881925e305c2c2044105546e0b7a8ca1d8c523d8584be05a
sha512: 4f39dbe7222b0f3bb3bb92109b470d407ec76b3741e4cc53551913a162df7d2de0f54bf723485b39d990a859a052cf2b4378ca771fbee8495260dda42e421170
ssdeep: 12288:Amp9XVk3rNq8srw+ZdKSsWItO8n+D0s+rIJEgVemHgxA6EfJNZ2xRul:VlQNqHMWKKcAFrJFeHx9AKxwl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Nanocore.S15454114 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69429
CAT-QuickHealTrojan.Nanocore.S15454114
ALYacTrojan.GenericKDZ.69429
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Kryptik.4!c
K7AntiVirusTrojan ( 0056c6e51 )
BitDefenderTrojan.GenericKDZ.69429
K7GWTrojan ( 0056c6e51 )
Cybereasonmalicious.dc7a9e
Invinceaheuristic
SymantecInfostealer.Lokibot!43
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Dropper.LokiBot-9312584-0
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
ViRobotTrojan.Win32.S.Agent.868864.AK
TencentWin32.Trojan.Kryptik.Dztx
Ad-AwareTrojan.GenericKDZ.69429
ComodoTrojWare.Win32.UMal.czyzc@0
F-SecureTrojan.TR/Kryptik.nbvyy
DrWebBackDoor.SpyBotNET.25
TrendMicroTROJ_GEN.R049C0DHE20
FortinetW32/Injector.EMZL!tr
FireEyeGeneric.mg.1c619b1dc7a9ed8e
SophosMal/Generic-S
IkarusTrojan.Inject
CyrenW32/Trojan.NDYQ-9233
JiangminTrojan.Kryptik.cbt
WebrootW32.Trojan.Gen
AviraTR/Kryptik.nbvyy
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Injector
ArcabitTrojan.Generic.D10F35
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftTrojan:Win32/NanoCore.VD!MTB
CynetMalicious (score: 85)
AhnLab-V3Suspicious/Win.Delphiless.X2091
McAfeeFareit-FPQ!1C619B1DC7A9
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack.DLF
PandaTrj/CI.A
ZonerTrojan.Win32.92352
ESET-NOD32a variant of Win32/Injector.ENAB
TrendMicro-HouseCallTROJ_GEN.R049C0DHE20
RisingTrojan.Kryptik!1.CAC0 (CLOUD)
SentinelOneDFI – Suspicious PE
GDataTrojan.GenericKDZ.69429
BitDefenderThetaGen:NN.ZelphiF.34186.1GW@am85a7pi
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM05.1.38FF.Malware.Gen

How to remove Trojan.Nanocore.S15454114?

Trojan.Nanocore.S15454114 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment