Malware

Should I remove “ML/PE-A + Troj/Nivdort-CZ”?

Malware Removal

The ML/PE-A + Troj/Nivdort-CZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Nivdort-CZ virus can do?

  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself

How to determine ML/PE-A + Troj/Nivdort-CZ?


File Info:

name: 2329E46CC5F5F9E6C0D7.mlw
path: /opt/CAPEv2/storage/binaries/47776e39824c4342ff8bfbb260ea2809d606db3a181a3de7f4f05c4ed2f837b3
crc32: F88660EB
md5: 2329e46cc5f5f9e6c0d7830daabc6521
sha1: 129f839c4d01aba74bc8350fd5c2dd739daf6302
sha256: 47776e39824c4342ff8bfbb260ea2809d606db3a181a3de7f4f05c4ed2f837b3
sha512: 7297bac0d7d830223d8e3db5671667de3e2b24fcda89a01e1916bedbd35084fc2cfb6bf8d3c7f095eb261177ea2c923f1eadbab67a4be99c71aa999bbf803733
ssdeep: 6144:fhR2HXEXcZzcBXWGjihh9UaFvghpa6Z+MAtaeICuaRolbVm01cEEhV:JwbR6+F+u4GV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D274F6ADDE9105DBDC42A4BC051533B7C7AEA00573EAB8CB93523B82597F8D4DA3160B
sha3_384: 84d06c1896c928c01cea05c4f85e1ce6af1c763b56ed08af4d6d7d1c2be84589daf8d22475addaea07d1044e25842824
ep_bytes: 558bec83ec08dd05f0e2440056dc0518
timestamp: 2015-12-23 04:20:23

Version Info:

0: [No Data]

ML/PE-A + Troj/Nivdort-CZ also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader18.23304
MicroWorld-eScanGen:Variant.Razy.11545
CAT-QuickHealAdware.Kazy.BC4
ALYacGen:Variant.Razy.11545
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004db0c61 )
K7GWTrojan ( 004da1e61 )
Cybereasonmalicious.cc5f5f
ArcabitTrojan.Razy.D2D19
BitDefenderThetaAI:Packer.4CB0F6081E
CyrenW32/Nivdort.F.gen!Eldorado
SymantecTrojan.Bayrob!gen6
ESET-NOD32a variant of Win32/Bayrob.AQ
TrendMicro-HouseCallTROJ_BAYROB.SM1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.11545
NANO-AntivirusTrojan.Win32.Dwn.dzojrb
SUPERAntiSpywareTrojan.Agent/Gen-Bayrob
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Razy.11545
EmsisoftGen:Variant.Razy.11545 (B)
ZillyaTrojan.Zbot.Win32.192814
TrendMicroTROJ_BAYROB.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.2329e46cc5f5f9e6
SophosML/PE-A + Troj/Nivdort-CZ
IkarusTrojan.Win32.Bayrob
JiangminTrojan.Bayrob.aq
AviraTR/Nivdort.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.164BE1C
MicrosoftTrojanSpy:Win32/Nivdort
GDataGen:Variant.Razy.11545
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R170875
McAfeeTrojan-FHPD!2329E46CC5F5
MAXmalware (ai score=84)
VBA32BScope.TrojanSpy.Nivdort
MalwarebytesTrojan.Bayrob.Generic
APEXMalicious
RisingTrojan.Bayrob!1.A350 (CLASSIC)
YandexTrojan.GenAsa!LJDUjmaTjd4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bayrob.AQ!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove ML/PE-A + Troj/Nivdort-CZ?

ML/PE-A + Troj/Nivdort-CZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment