Spy Trojan

About “TrojanSpy:Win32/Nivdort.DA” infection

Malware Removal

The TrojanSpy:Win32/Nivdort.DA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Nivdort.DA virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine TrojanSpy:Win32/Nivdort.DA?


File Info:

name: E8D216371DE2B8C65575.mlw
path: /opt/CAPEv2/storage/binaries/00e4676cec3b0895e5e2716766fc36a9521220debada5f114a556ee1782016d1
crc32: 94C5D8D3
md5: e8d216371de2b8c65575aea83ac0a07c
sha1: 3eb0d0d9798e19e3d02e3f491da79ffd0d303549
sha256: 00e4676cec3b0895e5e2716766fc36a9521220debada5f114a556ee1782016d1
sha512: 0e60cfde02900f1e315046abbd165b26bc7fd3c275032de22f942e9548257339532c96952a7c42dda6704a6b04ed5aab357f5dd89552984d1a9ed879880e17d0
ssdeep: 6144:cwjMFnXQTTEVX9M+7OGSEefzE+ak4zqp:cwWQTTk7OGNefzEDkcw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D634BF27E6482127C91B727C4F1A7BE5A4BF71326621660D83EC29CC5CA17DDB63312B
sha3_384: cf5452ab628827916e8c7443777608108bcf9517d1a75258043aba87d79911aa74099b8cb7da7e41172bb5635fd52bd3
ep_bytes: 66a16add43000fbf0d56e343009803c8
timestamp: 2014-12-22 14:28:20

Version Info:

0: [No Data]

TrojanSpy:Win32/Nivdort.DA also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Lazy.219050
FireEyeGeneric.mg.e8d216371de2b8c6
CAT-QuickHealTrojanSpy.Nivdort.DR3
SkyhighBehavesLike.Win32.Trojan.dc
McAfeeTrojan-FHQT!E8D216371DE2
VIPREGen:Variant.Lazy.219050
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004dc2a31 )
K7GWTrojan ( 004dc2a31 )
Cybereasonmalicious.9798e1
ArcabitTrojan.Lazy.D357AA
BaiduWin32.Trojan.Generic.ay
SymantecTrojan.Bayrob!gen6
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Bayrob.BA
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Lazy.219050
NANO-AntivirusTrojan.Win32.Nivdort.eabkyr
AvastWin32:Vupa [Cryp]
SophosMal/Bayrob-A
F-SecureHeuristic.HEUR/AGEN.1318579
DrWebTrojan.DownLoader46.34512
TrendMicroTROJ_BAYROB.SM7
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Lazy.219050 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Bayrob.itb
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1318579
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.TSGeneric
Kingsoftmalware.kb.a.1000
MicrosoftTrojanSpy:Win32/Nivdort.DA
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Lazy.219050
VaristW32/Nivdort.G.gen!Eldorado
AhnLab-V3Trojan/Win32.Nivdort.C1317722
Acronissuspicious
BitDefenderThetaAI:Packer.6C7B969F1E
ALYacGen:Variant.Lazy.219050
VBA32BScope.TrojanSpy.Nivdort
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_BAYROB.SM7
RisingTrojan.Bayrob!1.A3C6 (CLASSIC)
YandexTrojan.Agent!7B+rBQFQ5I4
IkarusTrojan.Win32.Bayrob
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bayrob.AQ!tr
AVGWin32:Vupa [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanSpy:Win32/Nivdort.DA?

TrojanSpy:Win32/Nivdort.DA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment