Trojan

Trojan:MSIL/Nagoot.A removal instruction

Malware Removal

The Trojan:MSIL/Nagoot.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Nagoot.A virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a copy of itself
  • Collects information to fingerprint the system

How to determine Trojan:MSIL/Nagoot.A?


File Info:

crc32: 4C549FB6
md5: d013d02038ffefc6698a5286be733b56
name: upload_file
sha1: 683b768823f3345c0c23c654a2092b8e469135ba
sha256: 0b03b352baf2bb90629f67b3b2b38a234875d3d96aa852452a873348b167f67c
sha512: c074480bb326ee7695fa0fee5b2ef0b9555481bc1c8d085d0d870aa13a91f33019f30463b5150955713afa731a1d7aca72e498eb20722d8ebf813f437c32568f
ssdeep: 6144:22HD1a+RPy8RNsLySqVnCaqDvzPUNGiDi:22HD1a+tRNonacvzM
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: test.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: test.exe

Trojan:MSIL/Nagoot.A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.561344
FireEyeGeneric.mg.d013d02038ffefc6
ALYacGen:Variant.Razy.561344
MalwarebytesBackdoor.NanoCore
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Variant.Razy.561344
Cybereasonmalicious.038ffe
BitDefenderThetaGen:NN.ZemsilF.34566.pm0@aq7Q!Sj
CyrenW32/Nagoot.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
BaiduMSIL.Trojan.Injector.l
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Bladabindi-6860329-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Inject.ephlgw
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareGen:Variant.Razy.561344
SophosTroj/MSIL-EBL
ComodoBackdoor.Win32.Fynloski.R@65x1ck
F-SecureTrojan.TR/Inject.sbbeiko
DrWebTrojan.DownLoader12.46082
InvinceaML/PE-A + Troj/MSIL-EBL
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftGen:Variant.Razy.561344 (B)
IkarusTrojan.MSIL.Injector
AviraTR/Inject.sbbeiko
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojan:MSIL/Nagoot.A
ArcabitTrojan.Razy.D890C0
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.561344
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Inject.C902541
McAfeeGenericRXAG-IX!D013D02038FF
VBA32CIL.StupidPInvoker-1.Heur
CylanceUnsafe
ESET-NOD32a variant of MSIL/Injector.IKV
YandexTrojan.Agent!3M9Xw0n1gEY
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Injector.IFP!tr
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.60f

How to remove Trojan:MSIL/Nagoot.A?

Trojan:MSIL/Nagoot.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment