Trojan

How to remove “TrojanDropper:Win32/Nuwar!B”?

Malware Removal

The TrojanDropper:Win32/Nuwar!B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Nuwar!B virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine TrojanDropper:Win32/Nuwar!B?


File Info:

name: CDE48702E784B9F06691.mlw
path: /opt/CAPEv2/storage/binaries/040be9f4a3a883d16fafe9e493c13039763b4347ca60c67075fcbb96ab2c96e4
crc32: 1BE4B103
md5: cde48702e784b9f0669105b6b29a548c
sha1: 1f18b1f0c10fde68ba888a133b45acb968d8d9e9
sha256: 040be9f4a3a883d16fafe9e493c13039763b4347ca60c67075fcbb96ab2c96e4
sha512: aca320e4050a7a35ead92f36b89a61621cb1d764f57d20925e567f83f13ffbce583d10c5a574d8a9dc2f2e46f96817e2d3c735f561f46f357430d2db57810d0b
ssdeep: 3072:dNr8no2lEfcxvUM4jQUpqGzi+kpBUMZgEG:dNr92aOvUM4jNWDFZgv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CC3029DF25823F7C0A726B610C8F7E4153C34740FD3E6578366629C68B4AADA7BC885
sha3_384: c66b678cefdeceaad0ef2732a3aedca9483d7397e8157e3c8144ff67aec603cb8e267cdd9d3619975ac7a54671c6a45b
ep_bytes: 5589e583ec08c7042402000000ff1510
timestamp: 2008-03-10 13:50:32

Version Info:

0: [No Data]

TrojanDropper:Win32/Nuwar!B also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Zhelatin.kZ0f
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.cde48702e784b9f0
SkyhighBehavesLike.Win32.DNSChanger.cc
ALYacTrojan.Peed.IWW
Cylanceunsafe
VIPRETrojan.Peed.IWW
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 000789db1 )
AlibabaWorm:Win32/Nuwar.8a5ecd07
K7GWEmailWorm ( 000789db1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Peacomm
ESET-NOD32probably a variant of Win32/Nuwar.Gen
APEXMalicious
ClamAVWin.Trojan.Peed-129
KasperskyEmail-Worm.Win32.Zhelatin.vg
BitDefenderTrojan.Peed.IWW
NANO-AntivirusTrojan.Win32.Zhelatin.xkmoj
MicroWorld-eScanTrojan.Peed.IWW
AvastWin32:Zhelatin-CIT [Wrm]
SophosML/PE-A
F-SecureWorm.WORM/Zhelatin.pc
DrWebTrojan.Packed.357
ZillyaWorm.Zhelatin.Win32.6855
TrendMicroWORM_NUWAR.AR
EmsisoftTrojan.Peed.IWW (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Peed.IWW
JiangminWorm/Zhelatin.egp
WebrootW32.Malware.Gen
VaristW32/StormWorm.gen1
AviraWORM/Zhelatin.pc
Antiy-AVLWorm[Email]/Win32.Zhelatin
Kingsoftmalware.kb.a.1000
XcitiumEmailWorm.Win32.Zhelatin.VG@fb1gk
ArcabitTrojan.Peed.IWW
ViRobotI-Worm.Win32.Zhelatin.117249
ZoneAlarmEmail-Worm.Win32.Zhelatin.vg
MicrosoftTrojanDropper:Win32/Nuwar.gen!B
GoogleDetected
AhnLab-V3Win32/Zhelatin.worm.13824
McAfeeW32/Nuwar@MM.u
MAXmalware (ai score=100)
VBA32Trojan-Downloader.Revelation.Tibs.B
PandaW32/Nuwar.VI.worm
TrendMicro-HouseCallWORM_NUWAR.AR
RisingWorm.Mail.Win32.Zhelatin.wrd (CLASSIC)
YandexWorm.DR.Zhelatin.Gen.4
IkarusPacker.Win32.Tibs
MaxSecureTrojan.Zhelatin.vg
FortinetW32/Dorf.AX!tr
BitDefenderThetaGen:NN.ZexaF.36744.huW@aKxDKVb
AVGWin32:Zhelatin-CIT [Wrm]
Cybereasonmalicious.0c10fd
DeepInstinctMALICIOUS

How to remove TrojanDropper:Win32/Nuwar!B?

TrojanDropper:Win32/Nuwar!B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment