Trojan

Trojan.Win32.NanoBot.zsu removal instruction

Malware Removal

The Trojan.Win32.NanoBot.zsu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.NanoBot.zsu virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to remove evidence of file being downloaded from the Internet
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • CAPE detected the NanoCore malware family
  • Collects information to fingerprint the system

How to determine Trojan.Win32.NanoBot.zsu?


File Info:

name: AB031666C9B64F189E76.mlw
path: /opt/CAPEv2/storage/binaries/a3dde8e99bfdba5f0c58acf0398c62c4b7ffaf1d34ef4488cbfa76c1772405e2
crc32: D8DA7E8A
md5: ab031666c9b64f189e76584712ce2d36
sha1: ab983cf027e8f035bac8b851787a3ce8f9f47fd7
sha256: a3dde8e99bfdba5f0c58acf0398c62c4b7ffaf1d34ef4488cbfa76c1772405e2
sha512: c014e20b0c13e60b4593e01d917a9f6d5c82e6c71a5170c140c9b901af1352b899583f16591e9343c6a84a868c667ad3670e1c7aa1d71559dbd2e49241d65f5a
ssdeep: 98304:Wviz/27qWGq/TzuqCDl2Ptao7jBPKeCLiNV:Wviq75/Tzuf+P1/NV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T186F533417ACC0527C57013B124FD23DB1FF8BCB212BAAB4A70C5514E19964E1BAF6FA6
sha3_384: 84695d4e2adf7d4e7ad6f45c3301f60b32ece0d7f8d8a893c4cf294630f2d8e7684be5ca0b7a8f4a7ba519152afd4439
ep_bytes: e8f0060000e9000000006a5868b87240
timestamp: 2022-05-24 22:49:06

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 11.00.17763.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.17763.1
Translation: 0x0409 0x04b0

Trojan.Win32.NanoBot.zsu also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.DownLoader26.43550
MicroWorld-eScanTrojan.Dropper.ZNM
FireEyeGeneric.mg.ab031666c9b64f18
ALYacTrojan.Dropper.ZNM
CylanceUnsafe
VIPRETrojan.Dropper.ZNM
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.027e8f
VirITTrojan.Win32.Dnldr26.CMLA
CyrenDropper.BJYT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RVE
ClamAVWin.Malware.Generic-6895514-0
KasperskyTrojan.Win32.NanoBot.zsu
AvastWin32:Trojan-gen
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Cab
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
MalwarebytesGeneric.Trojan.Malicious.DDS
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.RVD!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan.Win32.NanoBot.zsu?

Trojan.Win32.NanoBot.zsu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment