Trojan

Trojan:MSIL/NanoCore.DHA!MTB removal guide

Malware Removal

The Trojan:MSIL/NanoCore.DHA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/NanoCore.DHA!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan:MSIL/NanoCore.DHA!MTB?


File Info:

crc32: B0C55D59
md5: 504d925b4ba77f4195fcdbbd5ef60a12
name: dialo.exe
sha1: bf4c89300ca87b21c6b9c02b231a1a20bef7f607
sha256: c8a466fb75baf58bb0864f6f198b70c3b4c934f6a0814d59798df4626e724045
sha512: b2334ab796130b2eec3c3277c272894e0a9749cb87bb11c6f601dfdb6da7ee5736bd2ed6d1995b8c30df566668ad2564fb8c15cd346408e74b5efbe0b0b58654
ssdeep: 6144:dd5ngfum2OtV6XPuGJM5zgmstMP64OBrfc24xxIepcvaxjsbXOQVml:dngfumxVmPs5zgNtMXO6pLySjsaL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: LJuvNQz.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Menu
ProductVersion: 1.0.0.0
FileDescription: Menu
OriginalFilename: LJuvNQz.exe

Trojan:MSIL/NanoCore.DHA!MTB also known as:

DrWebTrojan.PackedNET.237
MicroWorld-eScanTrojan.GenericKD.33549063
Qihoo-360Generic/Trojan.PSW.374
McAfeeArtemis!504D925B4BA7
MalwarebytesTrojan.MalPack.ADC
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005628f81 )
BitDefenderTrojan.GenericKD.33549063
K7GWTrojan ( 005628f81 )
Cybereasonmalicious.00ca87
TrendMicroTROJ_GEN.R002C0DCI20
CyrenW32/MSIL_Kryptik.AIS.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
GDataTrojan.GenericKD.33549063
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojanPSW:MSIL/Injector.c2ce4756
AvastWin32:Malware-gen
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareTrojan.GenericKD.33549063
SophosMal/Kryptik-DL
F-SecureTrojan.TR/Injector.kijsm
ZillyaTrojan.Injector.Win32.693208
McAfee-GW-EditionRDN/Generic PWS.y
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.33549063 (B)
IkarusTrojan.MSIL.Inject
WebrootW32.Trojan.Gen
AviraTR/Injector.kijsm
ArcabitTrojan.Generic.D1FFEB07
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
MicrosoftTrojan:MSIL/NanoCore.DHA!MTB
AhnLab-V3Trojan/Win32.MSILInject.R328918
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.33549063
MAXmalware (ai score=80)
ESET-NOD32a variant of MSIL/Injector.UTA
TrendMicro-HouseCallTROJ_GEN.R002C0DCI20
TencentMsil.Trojan-qqpass.Qqrob.Ssgz
YandexTrojan.AvsArher.bSIdr7
SentinelOneDFI – Malicious PE
FortinetMSIL/GenKryptik.EGIJ!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.74499699.susgen

How to remove Trojan:MSIL/NanoCore.DHA!MTB?

Trojan:MSIL/NanoCore.DHA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment