Trojan

Trojan.Win32.NanoBot.vst malicious file

Malware Removal

The Trojan.Win32.NanoBot.vst is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.NanoBot.vst virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
marci.hopto.org

How to determine Trojan.Win32.NanoBot.vst?


File Info:

crc32: 0B8A72F3
md5: 93ddfd25543ecf58b4eafc3cbff6e9a6
name: jnnnn.exe
sha1: 253c4502865acee8e4bc75c15ac4c79637e02196
sha256: c35ad8f4da3acee2d05371dfcf2e256c57568709b834afa83b84a1f500901aa4
sha512: d85031596bc3512339c00653d44d3a3b44bc1c844fd95f6e723a24a70aab7b40c5dc9b4183629cdd565c96ed39983bff9def96e2e55a16f956ed12e8c03c95fb
ssdeep: 24576:ctb20pkaCqT5TBWgNQ7agAdQR66p/PYDriwDkhqvFHUdyYXvUYEIC0Elz5UE8Ma:FVg5tQ7agFR6+EOhqN0EApC008/shJ5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan.Win32.NanoBot.vst also known as:

MicroWorld-eScanTrojan.GenericKD.33529155
McAfeeArtemis!93DDFD25543E
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.33529155
K7GWTrojan ( 005621461 )
Cybereasonmalicious.2865ac
Invinceaheuristic
APEXMalicious
Paloaltogeneric.ml
GDataMSIL.Backdoor.Nancat.INBBAJ
KasperskyTrojan.Win32.NanoBot.vst
AlibabaTrojan:Win32/AutoitU.ali2000008
AegisLabTrojan.Win32.DarkKomet.mceq
AvastScript:SNH-gen [Trj]
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33529155 (B)
F-SecureTrojan.TR/AD.BDSNanoCoreClient.pzn
DrWebTrojan.KillProc2.9198
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
MaxSecureTrojan.Malware.300983.susgen
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.93ddfd25543ecf58
SophosMal/Generic-S
CyrenW32/AutoIt.OM.gen!Eldorado
AviraTR/AD.BDSNanoCoreClient.pzn
ArcabitTrojan.Generic.D1FF9D43
ZoneAlarmTrojan.Win32.NanoBot.vst
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Win-Trojan/AutoInj.Exp
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.AutoIt
ESET-NOD32a variant of Win32/Injector.Autoit.FDN
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_91%
FortinetAutoIt/Injector.FDH!tr
Ad-AwareTrojan.GenericKD.33529155
AVGScript:SNH-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360HEUR/QVM10.1.C7B1.Malware.Gen

How to remove Trojan.Win32.NanoBot.vst?

Trojan.Win32.NanoBot.vst removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment