Spy Trojan

TrojanSpy:Win32/Nivdort.AJ malicious file

Malware Removal

The TrojanSpy:Win32/Nivdort.AJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Nivdort.AJ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Authenticode signature is invalid

How to determine TrojanSpy:Win32/Nivdort.AJ?


File Info:

name: 59BDB3303208786A13DB.mlw
path: /opt/CAPEv2/storage/binaries/b4a498bbd3d859663392cc4a91237a76f68664852084ddb5f426ebf676d439e9
crc32: 03FE4215
md5: 59bdb3303208786a13db13d11cb59e6d
sha1: 57bebdd95509a6254f96367a143d5437155b62ae
sha256: b4a498bbd3d859663392cc4a91237a76f68664852084ddb5f426ebf676d439e9
sha512: ce476bd9e31ff9f35fead8f7ea8c323d99594f2bc0eea1163f8eaea0ddeb55a6cbc273713136671619abc25eac41e4502ed4face6f7cbae201acdfffe3a790ac
ssdeep: 6144:qOy6xWaKppI7RtRKrrozHV4oBiywKHaZtcDgARnk/KN9W+BIiuY:RxWaMSMAzHV4uqK66gAZbTNIiuY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13E748D15B0D0D0B5E0B2417A4A28EB3352BDBAB467B58ADB7FC80D8A17B44C17A77347
sha3_384: 648fcd8d575ebd15754a6ef9546ea95e9d371fb96f77af02ebc7da2cb9b1c1ae33bee6545adda778e5a9d337eed5a8b5
ep_bytes: e8bcd40000e9000000006a1468f83445
timestamp: 2015-05-11 06:11:03

Version Info:

0: [No Data]

TrojanSpy:Win32/Nivdort.AJ also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Bayrob.1
MicroWorld-eScanGen:Variant.Adware.Diley.1
FireEyeGeneric.mg.59bdb3303208786a
CAT-QuickHealTrojanSpy.Nivdort.OD4
McAfeePWS-FCCE!59BDB3303208
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004db0c61 )
K7GWTrojan ( 004db0c61 )
Cybereasonmalicious.032087
BitDefenderThetaAI:Packer.F187C5AC1E
SymantecDownloader.Upatre!g15
ESET-NOD32a variant of Win32/Bayrob.AA
TrendMicro-HouseCallTROJ_BAYROB.SM0
ClamAVWin.Malware.Bayrob-9785177-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Adware.Diley.1
Ad-AwareGen:Variant.Adware.Diley.1
EmsisoftGen:Variant.Adware.Diley.1 (B)
ComodoTrojWare.Win32.Scar.LSA@5refnq
BaiduWin32.Trojan.Generic.an
VIPRETrojan-Spy.Win32.Nivdort.ah (v)
TrendMicroTROJ_BAYROB.SM0
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
SophosML/PE-A + Troj/Nivdor-F
IkarusTrojan.Win32.Bayrob
GDataGen:Variant.Adware.Diley.1
AviraTR/Spy.Zbot.xbbeomq
ArcabitTrojan.Adware.Diley.1
MicrosoftTrojanSpy:Win32/Nivdort.AJ
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Kazy.C837501
VBA32BScope.Trojan.Bayrob
ALYacGen:Variant.Adware.Diley.1
MAXmalware (ai score=62)
MalwarebytesTrojan.Agent
APEXMalicious
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazp4QSdsHs+fzFPwbFwXNjl6)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bayrob.T!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove TrojanSpy:Win32/Nivdort.AJ?

TrojanSpy:Win32/Nivdort.AJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment