Malware

Troj/Nivdort-CZ removal tips

Malware Removal

The Troj/Nivdort-CZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Nivdort-CZ virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Troj/Nivdort-CZ?


File Info:

name: 0229BC5210696A332F58.mlw
path: /opt/CAPEv2/storage/binaries/50ecf0544e77ce52a050aa3927c38dc801c5e5263b7b806c825580e8dc24c48c
crc32: 7029123B
md5: 0229bc5210696a332f58d93339cec648
sha1: 1937b7cf45072601b79a160af1a02db392bacffb
sha256: 50ecf0544e77ce52a050aa3927c38dc801c5e5263b7b806c825580e8dc24c48c
sha512: 7415f685b17717806538e14aca5379ef03d21f621493cb4fdda5b63b22f5c44a0f1e892ebf53b8d61b434ec99c3e1d5a255df507b750cb21a689ca869c266e87
ssdeep: 6144:Xt6k/MNBHOILKOjZRNr8epiktK982afcMKYj3uydSL3airiLMyMXCot8XD9Kgrcg:4kSBuIeockr2afEYaye3hrsZcu9KpQX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1497418FEED8181DEEC42E4BC85756773E7AD20543AA421DF62403B9419BD6E4D83A30B
sha3_384: 9791a6b8465db6bcf860cdf46e18664448cb2a117aefeff477295e16bcc40eaacf548bf62119c32270f24be8180902fa
ep_bytes: 558becd9057cd0440083ec08dc2530be
timestamp: 2015-12-23 05:01:23

Version Info:

0: [No Data]

Troj/Nivdort-CZ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader18.36156
MicroWorld-eScanGen:Variant.Razy.11545
FireEyeGeneric.mg.0229bc5210696a33
CAT-QuickHealTrojanSpy.Nivdort.DR3
McAfeeTrojan-FHPD!0229BC521069
Cylanceunsafe
VIPREGen:Variant.Razy.11545
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanSpy:Win32/Nivdort.606266a7
K7GWTrojan ( 004da1e61 )
K7AntiVirusTrojan ( 004db0c61 )
BitDefenderThetaAI:Packer.40D0725C1E
SymantecTrojan.Bayrob!gen6
ESET-NOD32a variant of Win32/Bayrob.AQ
APEXMalicious
ClamAVWin.Trojan.Agent-1368835
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.11545
NANO-AntivirusTrojan.Win32.Dwn.dznzjk
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b72c9c
EmsisoftGen:Variant.Razy.11545 (B)
F-SecureTrojan.TR/Taranis.987
BaiduWin32.Trojan.Generic.bd
ZillyaTrojan.Bayrob.Win32.10763
TrendMicroTROJ_BAYROB.SM1
Trapminemalicious.high.ml.score
SophosTroj/Nivdort-CZ
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=82)
JiangminTrojan.Bayrob.hw
GoogleDetected
AviraTR/Taranis.987
VaristW32/Nivdort.F.gen!Eldorado
Antiy-AVLTrojan/Win32.Bayrob
Kingsoftmalware.kb.a.993
MicrosoftTrojanSpy:Win32/Nivdort.CW
ArcabitTrojan.Razy.D2D19
ViRobotTrojan.Win.Z.Bayrob.358912.B
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.11545
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R170875
VBA32BScope.TrojanSpy.Nivdort
ALYacGen:Variant.Razy.11545
MalwarebytesTrojan.Bayrob.Generic
TrendMicro-HouseCallTROJ_BAYROB.SM1
RisingTrojan.Bayrob!1.A350 (CLASSIC)
IkarusTrojan.Win32.Bayrob
MaxSecureTrojan.Malware.9019630.susgen
FortinetW32/Bayrob.AQ!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/Genetic.gen
alibabacloudTrojan:Win/Bayrob.AQ

How to remove Troj/Nivdort-CZ?

Troj/Nivdort-CZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment