Spy Trojan

TrojanSpy:Win32/Nivdort.CB removal tips

Malware Removal

The TrojanSpy:Win32/Nivdort.CB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Nivdort.CB virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanSpy:Win32/Nivdort.CB?


File Info:

name: DCF53CCBDC3A13621CA1.mlw
path: /opt/CAPEv2/storage/binaries/534edc66e44a8155fc974bf0d80f46be0300e9d7d86ec8db2f156380a33b03db
crc32: B2F5F319
md5: dcf53ccbdc3a13621ca12eb750bf41a6
sha1: efef2abccbc4f3f3ab0a51bbf49fb56ecca8c869
sha256: 534edc66e44a8155fc974bf0d80f46be0300e9d7d86ec8db2f156380a33b03db
sha512: a5f419bc5b2a83a43151f591a164bca0d7d6d35b3f6a721f8d9a384b5be094f9d4268924accfabf1575758d500f48dd957831c07b2af137ed329bf0b5a8f6608
ssdeep: 6144:wxDDRWlCSqq2zcGjW0YgkTGXzf2wxdewd9U86crZZAGFIwmMsDhM3Y3b:wxDW2AAW0YgkTsFxdeTSAGFIltuu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17794380478D3C07AD2E381F589AAB22305B9AD6523F545C7BFD5888C5BE80D1AA7770F
sha3_384: 8c11c2ecf2ca04906572f6e18ae95582f5322a4da68326699df8f2c0eb7bb57cb20932f153cede68270e4294ca496de0
ep_bytes: e8bcd40000e9000000006a1468682b46
timestamp: 2015-11-11 23:20:18

Version Info:

0: [No Data]

TrojanSpy:Win32/Nivdort.CB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Mikey.27775
CAT-QuickHealTrojanSpy.Nivdort.DR3
ALYacGen:Variant.Mikey.27775
MalwarebytesMalware.AI.4163257439
K7AntiVirusTrojan ( 004da8bd1 )
K7GWTrojan ( 004da8bd1 )
Cybereasonmalicious.bdc3a1
BaiduWin32.Trojan.Kryptik.ry
CyrenW32/Nivdort.I.gen!Eldorado
SymantecTrojan.Bayrob!gen6
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Bayrob.AA
APEXMalicious
ClamAVWin.Malware.Razy-6979265-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Mikey.27775
AvastWin32:MalwareX-gen [Trj]
EmsisoftGen:Variant.Mikey.27775 (B)
F-SecureHeuristic.HEUR/AGEN.1318777
VIPREGen:Variant.Mikey.27775
TrendMicroTROJ_BAYROB.SM9
McAfee-GW-EditionBehavesLike.Win32.Backdoor.gh
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.dcf53ccbdc3a1362
SophosTroj/Nivdor-C
GDataGen:Variant.Mikey.27775
GoogleDetected
AviraHEUR/AGEN.1318777
MAXmalware (ai score=80)
ArcabitTrojan.Mikey.D6C7F
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanSpy:Win32/Nivdort.CB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Nivdort.C1263691
Acronissuspicious
McAfeeGeneric-FAWY!DCF53CCBDC3A
VBA32BScope.TrojanSpy.Nivdort
Cylanceunsafe
TrendMicro-HouseCallTROJ_BAYROB.SM9
RisingTrojan.Win32.Bayrod.b (CLASSIC)
YandexTrojan.GenAsa!ghcVIcpH9NA
IkarusTrojan.Win32.Bayrob
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bayrob.BM!tr
BitDefenderThetaAI:Packer.7CE0A3481E
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove TrojanSpy:Win32/Nivdort.CB?

TrojanSpy:Win32/Nivdort.CB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment