Trojan

TrojanDownloader:Win32/Nitedrem.F!bit removal

Malware Removal

The TrojanDownloader:Win32/Nitedrem.F!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Nitedrem.F!bit virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Nitedrem.F!bit?


File Info:

crc32: 37D1BE5E
md5: 92c61ba874dc0f5384bae1e3a312e1a9
name: 92C61BA874DC0F5384BAE1E3A312E1A9.mlw
sha1: 0f5b2307b6d6cb38401c2b70dca5e94ddcf5c6e3
sha256: 197f47bea1c77a95a61594b69cd5c67b3f99d0dfd5cd78b3904bb994adee11b7
sha512: ac89000d414403e6de99ecb1e72874c9c73f42d44823569f28dcbf3c345069c0611ac7f40aae8dd349603c4ce7829ee4763b85cbdfdfcb03dc14241250c8f483
ssdeep: 3072:DmQml1lVcVyK33rmBQgeaxWeURy38EUYkJ2WKlftfUpzSd9VVV3zSVGyhi4:Dm5/lVcVyKHSzxNSYkdKjx4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Nitedrem.F!bit also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.36069883
FireEyeGeneric.mg.92c61ba874dc0f53
CAT-QuickHealTrojan.Inject
ALYacTrojan.GenericKD.36069883
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 004edccf1 )
BitDefenderTrojan.GenericKD.36069883
K7GWTrojan-Downloader ( 004edccf1 )
Cybereasonmalicious.7b6d6c
BitDefenderThetaGen:NN.ZexaF.34804.mqW@a4HMsAFi
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Gh0stRAT-6991620-0
KasperskyTrojan.Win32.Inject.adqge
AlibabaTrojan:Win32/Kryptik.4bbbaf93
NANO-AntivirusTrojan.Win32.Inject.elthiv
ViRobotTrojan.Win32.Z.Inject.196608.AT
TencentMalware.Win32.Gencirc.114a2253
Ad-AwareTrojan.GenericKD.36069883
EmsisoftTrojan.GenericKD.36069883 (B)
ComodoMalware@#29sean222iidd
F-SecureTrojan.TR/Crypt.ZPACK.pydna
DrWebTrojan.DownLoader23.56012
ZillyaTrojan.Inject.Win32.207658
TrendMicroTROJ_GEN.R002C0PAA21
McAfee-GW-EditionGenericRXND-FT!92C61BA874DC
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
AviraTR/Crypt.ZPACK.pydna
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Inject
MicrosoftTrojanDownloader:Win32/Nitedrem.F!bit
ArcabitTrojan.Generic.D22661FB
ZoneAlarmTrojan.Win32.Inject.adqge
GDataTrojan.GenericKD.36069883
CynetMalicious (score: 90)
McAfeeGenericRXND-FT!92C61BA874DC
VBA32Trojan.Inject
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.FORR
TrendMicro-HouseCallTROJ_GEN.R002C0PAA21
RisingDownloader.Nitedrem!8.5E8D (C64:YzY0OlfBxy9mrJju)
YandexTrojan.Inject!OvPu0r+SxfY
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/Generic.AC.3D53FF!tr
WebrootW32.Adware.Installcore
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/Trojan.a3b

How to remove TrojanDownloader:Win32/Nitedrem.F!bit?

TrojanDownloader:Win32/Nitedrem.F!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment