Trojan

How to remove “Trojan:Win32/Nanocore.B!MTB”?

Malware Removal

The Trojan:Win32/Nanocore.B!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Nanocore.B!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Trojan:Win32/Nanocore.B!MTB?


File Info:

name: 489FC51AB9732B0DFF8B.mlw
path: /opt/CAPEv2/storage/binaries/0d8f67278b9975e53cef73e21b4be04b7689d9e3bd8408772361b7ff5c97b3ec
crc32: 44EE708A
md5: 489fc51ab9732b0dff8bdae188f6cf8e
sha1: 9429e6352d750da6322e7f5ae2c8d71f72991c2f
sha256: 0d8f67278b9975e53cef73e21b4be04b7689d9e3bd8408772361b7ff5c97b3ec
sha512: 8073435c638908efda2591e2569a35a9337bd6ad37d14effd9d27c3c575d6f4c2f2a4cf681dad47c3daf52428ba54726e67f481c184a291f3246c7307af4f918
ssdeep: 12288:FUXBVVN+jL7n5fsr+7YHQp6JCkvOgUZRkZeykx:Fe3VNy75YzIPeOpLk0dx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13EB4BF36F2D04437D2732A3C9C5B5E64AC3EBE503E2958462BE81D4C5F39782396929F
sha3_384: ceacb5ea975bc68f9b6f146731a62d28593898d71deac3b527ba83d05de2c0ddc496d145992cf64cedb6f74d41407e76
ep_bytes: 558bec83c4f0b84ceb4400e8206ffbff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: GNgn.org>
License: This program is free softrib ande terms of the GNU General Public License;see www.gnu.org/copyleft/gpl.html.
FileDescription: Gperf: generatfect hash function from a key set
FileVersion: 3.0.1.1765
InternalName: gperf
LegalCopyright: © e Softwre Fof.org>
LegalTrademarks: GNUerf®
OriginalFilename: gperf.exe
ProductName: Gperf
ProductVersion: 3.0.1.1765
SpecialBuild: GNU in32
WWW: http://wf.html
Translation: 0x0409 0x04e4

Trojan:Win32/Nanocore.B!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Kryptik.4!c
DrWebTrojan.Nanocore.23
MicroWorld-eScanGen:Variant.Ransom.Loki.9409
ClamAVWin.Dropper.LokiBot-7768036-0
FireEyeGeneric.mg.489fc51ab9732b0d
SkyhighBehavesLike.Win32.Generic.hc
McAfeeFareit-FSK!489FC51AB973
Cylanceunsafe
VIPREGen:Variant.Ransom.Loki.9409
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005687bd1 )
BitDefenderGen:Variant.Ransom.Loki.9409
K7GWTrojan ( 005687bd1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ransom.Loki.D24C1
BitDefenderThetaGen:NN.ZelphiF.36744.GG0@aitZWCki
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ELUM
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/Nanocore.da147974
NANO-AntivirusTrojan.Win32.Nanocore.hlghgv
RisingTrojan.Kryptik!1.C625 (CLASSIC)
SophosMal/Fareit-AA
F-SecureHeuristic.HEUR/AGEN.1331248
ZillyaDropper.Agent.Win32.426686
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Ransom.Loki.9409 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Kryptik.arf
GoogleDetected
AviraHEUR/AGEN.1331248
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Wacatac
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Nanocore.B!MTB
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
GDataGen:Variant.Ransom.Loki.9409
VaristW32/Delf.KP.gen!Eldorado
AhnLab-V3Suspicious/Win.Delphiless.X2059
VBA32Trojan.Kryptik
ALYacGen:Variant.Ransom.Loki.9409
DeepInstinctMALICIOUS
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
ZonerTrojan.Win32.91688
TencentMalware.Win32.Gencirc.10bc71a7
IkarusTrojan.Inject
MaxSecureTrojan.Malware.73736783.susgen
FortinetW32/Injector.EHDJ!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.52d750
AvastWin32:RATX-gen [Trj]

How to remove Trojan:Win32/Nanocore.B!MTB?

Trojan:Win32/Nanocore.B!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment