Trojan

How to remove “Trojan.Win32.Nobady.rxh”?

Malware Removal

The Trojan.Win32.Nobady.rxh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Nobady.rxh virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.Win32.Nobady.rxh?


File Info:

name: CD0466FA379819AF096A.mlw
path: /opt/CAPEv2/storage/binaries/f291e3df7c49753b1718c389df15f96e87bb96fb993f488486f065abc43c3107
crc32: 8E4B0C76
md5: cd0466fa379819af096ad6b5db7630a2
sha1: 7585462ffa91a5448caadf22498a33143dccadb8
sha256: f291e3df7c49753b1718c389df15f96e87bb96fb993f488486f065abc43c3107
sha512: 3e55587200ca0c17a50f6e58fc5a31d3dbca8b153b79c4383be2896c2140bac0c97ccdf0dca3507ca5ffe7c1bd0369f48eb1079beaa7f2d661a15c6283d19809
ssdeep: 6144:0h3QRXVNARknS5lIlkKyVkEl4R/l/z1SszzDH:zKRcS5jkxR9/zxLH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18D848C57F34D8B66E183037E2DDA8AF1672AFD38137782553039BB1E1A32A204776791
sha3_384: 3e123e47c546a90b87deddb1aeed6490b9235bb338262f983dce2d6a3aa68c490c06a662d4cff20e007e09359f1ada88
ep_bytes: 60be000000008a860010400080e85a80
timestamp: 2003-04-24 06:27:43

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: AdwTest.exe
LegalCopyright: TODO: (c) . All rights reserved.
OriginalFilename: AdwTest.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Trojan.Win32.Nobady.rxh also known as:

LionicTrojan.Win32.Nobady.4!c
MicroWorld-eScanGen:Variant.Barys.432000
FireEyeGeneric.mg.cd0466fa379819af
McAfeeGenericRXOB-DF!CD0466FA3798
MalwarebytesGeneric.Trojan.Malicious.DDS
ZillyaTrojan.Nobady.Win32.16904
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Nobady.2a432b68
K7GWTrojan ( 004b494b1 )
K7AntiVirusTrojan ( 004b494b1 )
CyrenW32/Agent.FTH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.WTK
APEXMalicious
ClamAVWin.Malware.Razy-9759519-0
KasperskyTrojan.Win32.Nobady.rxh
BitDefenderGen:Variant.Barys.432000
NANO-AntivirusTrojan.Win32.Patched.foubml
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Agent.zl
EmsisoftGen:Variant.Barys.432000 (B)
F-SecureTrojan.TR/Agent.vrcnq
DrWebTrojan.MulDrop5.42246
VIPREGen:Variant.Barys.432000
TrendMicroTROJ_GEN.R002C0DEE23
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
SophosMal/Agent-AWE
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BadJoke.J
GoogleDetected
AviraTR/Agent.vrcnq
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Agent.WTK
ArcabitTrojan.Barys.D69780
ZoneAlarmTrojan.Win32.Nobady.rxh
MicrosoftTrojan:Win32/Aenjaris.AL!bit
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.DF.R565972
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36250.w03@au93Zopi
ALYacGen:Variant.Barys.432000
VBA32SScope.Malware-Cryptor.Aenjaris
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEE23
RisingTrojan.Agent!1.A728 (CLASSIC)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.WTK!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.a37981
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Nobady.rxh?

Trojan.Win32.Nobady.rxh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment