Trojan

Trojan:Win32/NanoCore.VB!MTB (file analysis)

Malware Removal

The Trojan:Win32/NanoCore.VB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/NanoCore.VB!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/NanoCore.VB!MTB?


File Info:

crc32: A8A567E4
md5: 6e82029b0e42dc3836c0025dbb454533
name: 6E82029B0E42DC3836C0025DBB454533.mlw
sha1: 7966359e544dd9d9cf94b296b6612c2bb559d5a1
sha256: 8bd27979328a56420a99d028bac00909d0fed9f408e07b24f5c4e42fb85a1564
sha512: e449ebe97fe69873bd96d1aac6c7dcbff2a788b1c5380e2c4fa1c2347c00803e636b711e988abc997f1232c133ddf8a8f20383f0234b26ae6ef53954ec1cb15c
ssdeep: 768:PzmgrVxBWFHyL6cXmpNvYct90J/OJgHE+F5ZqwdORHDPGZT9:bmIzoSOcXmpezF2w8g5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Reaggress
FileVersion: 2.07
CompanyName: GAS-STAT
ProductName: skjol
ProductVersion: 2.07
FileDescription: GAS-STAT
OriginalFilename: Reaggress.exe

Trojan:Win32/NanoCore.VB!MTB also known as:

K7AntiVirusTrojan ( 005673f11 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader33.44743
ClamAVWin.Dropper.Nanocore-7867786-0
ALYacGen:Heur.PonyStealer.fm0@FGMx1Boi
CylanceUnsafe
ZillyaTrojan.Injector.Win32.740406
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Vebzenpak.eacaf2ec
K7GWTrojan ( 005673f11 )
Cybereasonmalicious.b0e42d
CyrenW32/Fareit.JS.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EMCD
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyTrojan.Win32.Vebzenpak.smc
BitDefenderGen:Heur.PonyStealer.fm0@FGMx1Boi
NANO-AntivirusTrojan.Win32.Dwn.hlgtmf
MicroWorld-eScanGen:Heur.PonyStealer.fm0@FGMx1Boi
TencentWin32.Trojan.Vebzenpak.Wsak
Ad-AwareGen:Heur.PonyStealer.fm0@FGMx1Boi
SophosMal/Generic-R + Mal/FareitVB-AE
ComodoMalware@#djs3ptfsd6bp
BitDefenderThetaGen:NN.ZevbaF.34170.fm0@aGMx1Boi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fareit.nz
FireEyeGeneric.mg.6e82029b0e42dc38
EmsisoftGen:Heur.PonyStealer.fm0@FGMx1Boi (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Vebzenpak
AviraTR/AD.VBCryptor.puddz
Antiy-AVLTrojan/Generic.ASMalwS.307EBFC
MicrosoftTrojan:Win32/NanoCore.VB!MTB
GDataGen:Heur.PonyStealer.fm0@FGMx1Boi
McAfeeFareit-FST!6E82029B0E42
MAXmalware (ai score=81)
VBA32Trojan.Wacatac
MalwarebytesTrojan.GuLoader
PandaTrj/Agent.AJS
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.SMTHH.hp
RisingDownloader.Guloader!1.C6E5 (CLASSIC)
YandexTrojan.Injector!DmN1VmaNOvo
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/GuLoader.VHIT!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml

How to remove Trojan:Win32/NanoCore.VB!MTB?

Trojan:Win32/NanoCore.VB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment