Trojan

Should I remove “Trojan.Nbi”?

Malware Removal

The Trojan.Nbi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Nbi virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Nbi?


File Info:

crc32: 0A780192
md5: 8ca6866dfbf3e978ba50e3c878bdf343
name: 8CA6866DFBF3E978BA50E3C878BDF343.mlw
sha1: b075abc26d34a2739ec6522ec47ec64e118fa9c2
sha256: edf0754b7dad01583e8475415f2af6ede69766bb57ebf5c5c10a55e992c9df5c
sha512: 8d3be6d7f7e838d4d3f1d20f1a709124e4076982f8d51531a8ffd87d66c46a6b7fb7926890425b04fe50d62a7a49a1588a4a5598449aa23d8e0107b526cd81f9
ssdeep: 24576:QLtduBCTW2vey48WHJoZzJijlxQtkTPo3aMitzjitqPk7Tg+pZB6m4PE:Y/TvRbWWfijlxOkTcaFvPWg+Nv4PE
type: MS-DOS executable, MZ for MS-DOS

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: TJprojMain
FileVersion: 1.00
OriginalFilename: TJprojMain.exe
ProductName: Project1

Trojan.Nbi also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44995433
FireEyeGeneric.mg.8ca6866dfbf3e978
CAT-QuickHealTrojan.Nbi
Qihoo-360HEUR/QVM18.1.0510.Malware.Gen
ALYacTrojan.GenericKD.44995433
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforMalware
K7AntiVirusP2PWorm ( 000dfe321 )
BitDefenderTrojan.GenericKD.44995433
K7GWP2PWorm ( 000dfe321 )
Cybereasonmalicious.dfbf3e
BitDefenderThetaGen:NN.ZevbaF.34804.yz3@aGmQMZki
CyrenW32/SysVenFak.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Sysvenfak-9809029-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.VB.icoups
RisingPUF.Pack-Enigma!1.BA33 (CLASSIC)
Ad-AwareTrojan.GenericKD.44995433
SophosML/PE-A + Troj/VB-KVP
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Generic.Win32.1278358
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.GenericKD.44995433 (B)
IkarusTrojan-Spy.Win32.Usteal
JiangminTrojan.Generic.gotjf
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.VB
MicrosoftTrojan:Script/Phonzy.A!ml
ArcabitTrojan.Generic.D2AE9369
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.44995433
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.C4248726
Acronissuspicious
McAfeeGenericRXMU-OG!8CA6866DFBF3
MAXmalware (ai score=83)
VBA32BScope.Trojan.Inject
MalwarebytesGeneric.Trojan.Injector.DDS
PandaTrj/Genetic.gen
ESET-NOD32Win32/VB.NBI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/VB.NBI
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureVirus.W32.Agent.xjgj

How to remove Trojan.Nbi?

Trojan.Nbi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment