Trojan

Trojan.Win32.Nobady.svd removal

Malware Removal

The Trojan.Win32.Nobady.svd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Nobady.svd virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.Win32.Nobady.svd?


File Info:

name: B3838164D35C97F439E3.mlw
path: /opt/CAPEv2/storage/binaries/5c2aa4db5cb8250bab010f5bffec806916b3cc40e9cfc2005db089b0277cb00c
crc32: 45DA2542
md5: b3838164d35c97f439e3d0aee5e59d28
sha1: 2da878383cc90062a566406dacb0143a7c592d38
sha256: 5c2aa4db5cb8250bab010f5bffec806916b3cc40e9cfc2005db089b0277cb00c
sha512: c384ecc9bc1220ff930cd713ae7ee47502cdc4d95d7c7a3d04fdec678fd0d6cda663303fc203f7ad4ccff48c6fb1771608a794c61ccc685dd1b83857dd286737
ssdeep: 6144:Jiyz+vqfjY8OaAHoQYepZ3S1kEl4R/l/z1SszzDH:QgjIay1YeLUkxR9/zxLH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11C847F1F77494772D1D30370198FCBA97A29BCB06365C6A73858B34D21B2B68C6B7392
sha3_384: 82d0a6a71a2f305f5af99eb3a3d301e8f4f439ed9fbd13e0cda9df494352af89190d33250d9bdd06c3fbc3fcc172b0c5
ep_bytes: 60bf000000008a9f00104000c0cbe288
timestamp: 2003-04-24 06:27:43

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: AdwTest.exe
LegalCopyright: TODO: (c) . All rights reserved.
OriginalFilename: AdwTest.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Trojan.Win32.Nobady.svd also known as:

LionicTrojan.Win32.Nobady.4!c
MicroWorld-eScanGen:Variant.Barys.432000
FireEyeGeneric.mg.b3838164d35c97f4
ALYacGen:Variant.Barys.432000
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004b494b1 )
AlibabaTrojan:Win32/Nobady.f84bd199
K7GWTrojan ( 004b494b1 )
Cybereasonmalicious.4d35c9
VirITTrojan.Win32.MulDrop5.CKMW
CyrenW32/Agent.FTH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.WTK
APEXMalicious
ClamAVWin.Malware.Razy-9759519-0
KasperskyTrojan.Win32.Nobady.svd
BitDefenderGen:Variant.Barys.432000
NANO-AntivirusTrojan.Win32.Drop.doguly
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Agent!1.A728 (CLASSIC)
EmsisoftGen:Variant.Barys.432000 (B)
F-SecureTrojan.TR/Agent.seoks
DrWebTrojan.MulDrop5.42246
VIPREGen:Variant.Barys.432000
TrendMicroTROJ_GEN.R002C0DEE23
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
SophosMal/Agent-AWE
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BadJoke.J
GoogleDetected
AviraTR/Agent.seoks
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Agent.WTK
ArcabitTrojan.Barys.D69780
ZoneAlarmTrojan.Win32.Nobady.svd
MicrosoftTrojan:Win32/Aenjaris.AL!bit
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.DF.R565972
Acronissuspicious
McAfeeGenericRXOB-DF!B3838164D35C
TACHYONTrojan/W32.Agent.374189.H
VBA32SScope.Malware-Cryptor.Aenjaris
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.32622
TrendMicro-HouseCallTROJ_GEN.R002C0DEE23
TencentTrojan.Win32.Agent.zl
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.WTK!tr
BitDefenderThetaGen:NN.ZexaF.36250.w03@au93Zopi
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Nobady.svd?

Trojan.Win32.Nobady.svd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment