Spy Trojan

TrojanSpy:Win32/Nivdort.CM removal instruction

Malware Removal

The TrojanSpy:Win32/Nivdort.CM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Nivdort.CM virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:80, 127.0.0.1:39780
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary

Related domains:

elementarimagine.com
mojoguia.com
pengthecon.com
themorrefk.com
tablewash.net
salthave.net
yourenjoy.net
lookloss.net
southabout.net
liarshot.net
ableeach.net
jumpgray.net
movegray.net
storykind.net
weakkind.net
afterwild.net
forcewild.net
afterjune.net
forcejune.net
afterbegan.net
forcebegan.net
afterkind.net
forcekind.net
sellwild.net
wednesdaywild.net
selljune.net
wednesdayjune.net
sellbegan.net
wednesdaybegan.net
sellkind.net
wednesdaykind.net
drivewild.net
nailwild.net
drivejune.net
nailjune.net
drivebegan.net
nailbegan.net
drivekind.net
nailkind.net
fieldboat.net
queenboat.net
fieldpress.net
queenpress.net
fieldrest.net
queenrest.net
fieldopen.net
queenopen.net
bothboat.net
gainboat.net
bothpress.net
gainpress.net
bothrest.net
gainrest.net
bothopen.net
gainopen.net
leastboat.net
faceboat.net
leastpress.net
facepress.net
leastrest.net
facerest.net
leastopen.net
faceopen.net
monthboat.net
walkboat.net
monthpress.net
walkpress.net
monthrest.net
walkrest.net
monthopen.net
walkopen.net
storyboat.net
weakboat.net
storypress.net
weakpress.net
storyrest.net
weakrest.net
storyopen.net
weakopen.net
afterboat.net
forceboat.net
afterpress.net
forcepress.net
afterrest.net
forcerest.net
afteropen.net
forceopen.net
sellboat.net
wednesdayboat.net
sellpress.net
wednesdaypress.net
sellrest.net
wednesdayrest.net
sellopen.net
wednesdayopen.net
driveboat.net
nailboat.net
drivepress.net
nailpress.net

How to determine TrojanSpy:Win32/Nivdort.CM?


File Info:

crc32: FDC2DAC4
md5: 2adf987ab1556769ebb0c18caf89a807
name: 2ADF987AB1556769EBB0C18CAF89A807.mlw
sha1: 5d52d3aecc7c0baacf775b753a577a2e9d009511
sha256: be727294665e5caea4501860cea56e4c78a30d51abda4177577604389cbedeae
sha512: 708b9a7c168970a14fa5a1348676ae3dfda42cf8d89ba6fbf1bd7de06fd2d213a2c5faac306b529e7436768cc5a913b6d9251062fc905113a15e81b239252460
ssdeep: 6144:Xx8SijafI0z8l+U/nxqJXXyBg4AjhAFgHkiJN7bEDydOROjSuDr8oMj:aSi2fnHXiq4AMgH9jwDyxDgJj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Nivdort.CM also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.30714
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.PT.CiW@bu8SYNp
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.46830
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Blocker.161e5b68
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ab1556
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GUMT
APEXMalicious
AvastWin32:Adware-gen [Adw]
ClamAVWin.Trojan.Agent-7039575-0
KasperskyTrojan-Ransom.Win32.Blocker.mblq
BitDefenderGen:Trojan.Heur.PT.CiW@bu8SYNp
NANO-AntivirusTrojan.Win32.Bayrob.eoftoh
MicroWorld-eScanGen:Trojan.Heur.PT.CiW@bu8SYNp
TencentWin32.Trojan.Blocker.Huqh
Ad-AwareGen:Trojan.Heur.PT.CiW@bu8SYNp
SophosMal/Generic-S + Troj/Nivdort-FN
ComodoTrojWare.Win32.Kryptik.GATE@5j70cv
F-SecureTrojan.TR/Crypt.XPACK.Gen
BitDefenderThetaAI:Packer.221F38F31E
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.2adf987ab1556769
EmsisoftGen:Trojan.Heur.PT.CiW@bu8SYNp (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.nwc
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_79%
Antiy-AVLTrojan/Generic.ASMalwS.2BFF32D
MicrosoftTrojanSpy:Win32/Nivdort.CM
ArcabitTrojan.Heur.PT.ED8F6C
AegisLabTrojan.Win32.Malicious.4!c
ZoneAlarmTrojan-Ransom.Win32.Blocker.mblq
GDataGen:Trojan.Heur.PT.CiW@bu8SYNp
McAfeeArtemis!2ADF987AB155
MAXmalware (ai score=61)
VBA32Trojan.Download
PandaTrj/CI.A
RisingTrojan.Generic@ML.90 (RDML:kQWkKyOWU5lNilc8xTBIRw)
YandexTrojan.GenAsa!F26f7mDCEfQ
IkarusTrojan-Spy.Win32.Nivdort
MaxSecureTrojan.Malware.74125374.susgen
FortinetW32/Kryptik.BCFJ!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove TrojanSpy:Win32/Nivdort.CM?

TrojanSpy:Win32/Nivdort.CM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment