Trojan

Trojan.Win32.Nimnul.ziu information

Malware Removal

The Trojan.Win32.Nimnul.ziu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Nimnul.ziu virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
qq274314920.top
fget-career.com

How to determine Trojan.Win32.Nimnul.ziu?


File Info:

crc32: 24BBAEB9
md5: 5845593a57f6331ea19717bcf4ce35aa
name: panda77.3.exe
sha1: b8b9772b03f120504186eae52b84c3ee96f466f0
sha256: a5512b0db1458f3ac8e2825757b229cc1b380b724759897891e9b74702298f02
sha512: a00df40688e9c4deaf89b060c425d0cc98b55b5d56173748b35b1d395882f05fc33516f29e3173870b3d8f9ba4fbccbf587984a9ef7ba1e9182fd862b60e2e3a
ssdeep: 98304:BqasXGGaJIWL8R+Ed2zs5SbWf+YFC4UG6rIXrMP8MSVPt:B6GQSsQaf+HpmrMUV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Nimnul.ziu also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.307227
FireEyeGeneric.mg.5845593a57f6331e
CAT-QuickHealTrojan.WacatacRI.S15111266
Qihoo-360Win32/Virus.WebToolbar.5b2
McAfeeGenericRXAA-AA!5845593A57F6
CylanceUnsafe
ZillyaTrojan.Nimnul.Win32.2529
AegisLabTrojan.Win32.Scar.luuu
SangforMalware
K7AntiVirusAdware ( 005071f51 )
BitDefenderGen:Variant.Zusy.307227
K7GWAdware ( 005071f51 )
Cybereasonmalicious.a57f63
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34196.@tW@a4yd23gb
CyrenW32/Trojan.LPSM-5741
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Trojan.Ramnit-1847
KasperskyTrojan.Win32.Nimnul.ziu
AlibabaTrojan:Win32/Nimnul.679c0984
RisingTrojan.Nimnul!8.1DE7 (CLOUD)
Ad-AwareGen:Variant.Zusy.307227
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
DrWebTrojan.Siggen7.38159
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WHF20
SophosMal/Generic-S
JiangminTrojan.Nystprac.bw
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftPUA:Win32/Vigua.A
ArcabitTrojan.Zusy.D4B01B
AhnLab-V3Malware/Win32.Generic.C4134329
ZoneAlarmTrojan.Win32.Nimnul.ziu
GDataGen:Variant.Zusy.307227
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
VBA32BScope.Backdoor.Poison
ALYacGen:Variant.Zusy.307227
MalwarebytesRiskWare.FlyStudio
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WHF20
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetRiskware/Nimnul
AVGWin32:Quolko
AvastWin32:Quolko
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.105198220.susgen

How to remove Trojan.Win32.Nimnul.ziu?

Trojan.Win32.Nimnul.ziu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment