Trojan

What is “Trojan.Win32.Nobady.rpt”?

Malware Removal

The Trojan.Win32.Nobady.rpt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Nobady.rpt virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.Win32.Nobady.rpt?


File Info:

name: 0A96D851D59EC24EE5FC.mlw
path: /opt/CAPEv2/storage/binaries/8f2b4539443c932d9e51f22455664098a9b21ac3200237eb48921b01d195b251
crc32: 99969813
md5: 0a96d851d59ec24ee5fc2bb5cdaeeb0e
sha1: 32a73dbd5f88000fef04ce3b8bd450894c9ef1e6
sha256: 8f2b4539443c932d9e51f22455664098a9b21ac3200237eb48921b01d195b251
sha512: 716be229459e9f9df4860841d62c63e06b700a45e3284be9937bbd7de19a9029660cadd3006ce9ac800dac3d88660c68213d528135c26be50d78e421f1306e6b
ssdeep: 6144:WPwQmJMIdZ0JWX6RtgVfIoqjintbHHkEl4R/l/z1SszzDH:WPwjJZQWLfIPSbnkxR9/zxLH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AD848D06F2888372C29303726AC9CAE47736FD7543B58A8F2794735F0633E68557A792
sha3_384: 930385fa3ddc7a3f0c1134bd46bee387a1fa961d1ff719579ecca0dfafc0ffab99e3b579476ae0586690ac48cd51b3b5
ep_bytes: 60bf000000008ab70010400080f672c0
timestamp: 2003-04-24 06:27:43

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: AdwTest.exe
LegalCopyright: TODO: (c) . All rights reserved.
OriginalFilename: AdwTest.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Trojan.Win32.Nobady.rpt also known as:

LionicTrojan.Win32.Nobady.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.432000
ClamAVWin.Malware.Razy-9759519-0
FireEyeGeneric.mg.0a96d851d59ec24e
McAfeeGenericRXOB-DF!0A96D851D59E
Cylanceunsafe
ZillyaTrojan.Nobady.Win32.17006
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Nobady.1ee518e8
K7GWTrojan ( 004b494b1 )
K7AntiVirusTrojan ( 004b494b1 )
CyrenW32/Agent.FTH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.WTK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Nobady.rpt
BitDefenderGen:Variant.Barys.432000
NANO-AntivirusTrojan.Win32.Patched.foubml
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Agent.zl
SophosMal/Agent-AWE
F-SecureTrojan.TR/Agent.bkxtt
DrWebTrojan.MulDrop5.42246
VIPREGen:Variant.Barys.432000
TrendMicroTROJ_GEN.R002C0DEE23
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
EmsisoftGen:Variant.Barys.432000 (B)
IkarusTrojan.Win32.Agent
GDataWin32.Trojan.BadJoke.J
AviraTR/Agent.bkxtt
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Agent.WTK
ArcabitTrojan.Barys.D69780
ZoneAlarmTrojan.Win32.Nobady.rpt
MicrosoftTrojan:Win32/Aenjaris.AL!bit
GoogleDetected
AhnLab-V3Trojan/Win.DF.R565972
Acronissuspicious
VBA32SScope.Malware-Cryptor.Aenjaris
ALYacGen:Variant.Barys.432000
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEE23
RisingTrojan.Agent!1.A728 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.WTK!tr
BitDefenderThetaGen:NN.ZexaF.36250.w03@au93Zopi
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Nobady.rpt?

Trojan.Win32.Nobady.rpt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment