Malware

What is “Generic.Nimda.D8E0A9BF”?

Malware Removal

The Generic.Nimda.D8E0A9BF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Nimda.D8E0A9BF virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Nimda.D8E0A9BF?


File Info:

name: 171AC8F946EA8CA62061.mlw
path: /opt/CAPEv2/storage/binaries/3bac38f9c5b272f51a7f85c992c8cfe0900c23b3bf1376d5fac5dc1773a6fdf7
crc32: 5A098512
md5: 171ac8f946ea8ca620613abbbaf20704
sha1: c868fd30dbb5efaf13a11198168146361275346e
sha256: 3bac38f9c5b272f51a7f85c992c8cfe0900c23b3bf1376d5fac5dc1773a6fdf7
sha512: 90f5a69e99a3472338a8a9e4f65aff14de65fe072dcb6c3d05d2956230463526020cc90b7b6d21993276d59548a2ee793eb496d7a4fa30956819126fae7d7717
ssdeep: 1536:SbbEBKksdaqqetP64visKldR3rzwV7Rq63JKqIPwBnj3:SbYyqetPgV3/w5RqOmwVj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6839E463C53C033E4164EB482D586C1DFBF69033AE3A17FEB5541891EB13A8166A7FA
sha3_384: 6867e78e8eb86c957ea88f824ceb1e98907b384eca2a5c13fbc232554e7f854c5f81951f28e37e3c3ddff08ebcc551c0
ep_bytes: e8b5170000e917feffff558bec81ec28
timestamp: 1997-04-07 03:01:30

Version Info:

Comments: Run this to install Kane & Lynch: Dead Men on your computer.
CompanyName: IO Interactive
FileDescription: Install Kane & Lynch: Dead Men
FileVersion: 1, 0, 0, 1
InternalName: Setup
LegalCopyright: Copyright (C) 2007
OriginalFilename: Setup.exe
ProductName: Setup Application
ProductVersion: 1, 0, 0, 1
Translation: 0x0409 0x04b0

Generic.Nimda.D8E0A9BF also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Nimda.4!c
AVGWin32:Agent-BARL [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Nimda.D8E0A9BF
FireEyeGeneric.mg.171ac8f946ea8ca6
McAfeeArtemis!171AC8F946EA
Cylanceunsafe
SangforWorm.Win32-Script.Save.Nimda
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitGeneric.Nimda.D8E0A9BF
BaiduWin32.Trojan.Agent.bf
SymantecW32.Madangel
tehtrisGeneric.Malware
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Worm.Brontok-88
BitDefenderGeneric.Nimda.D8E0A9BF
AvastWin32:Agent-BARL [Trj]
EmsisoftGeneric.Nimda.D8E0A9BF (B)
F-SecureMalware.W32/Chir.B
DrWebJS.Nimda
VIPREGeneric.Nimda.D8E0A9BF
McAfee-GW-EditionBehavesLike.Win32.Infected.mh
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminHeur:Trojan/VB
AviraW32/Chir.B
MAXmalware (ai score=85)
Antiy-AVLWorm[NET]/Win32.Nimda.gic
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGeneric.Nimda.D8E0A9BF
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36250.fq0@ai2aUnmi
ALYacGeneric.Nimda.D8E0A9BF
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
YandexI-Worm.Chir.B
IkarusWorm.Win32.Chir
FortinetW32/Chir.C!tr
DeepInstinctMALICIOUS

How to remove Generic.Nimda.D8E0A9BF?

Generic.Nimda.D8E0A9BF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment