Spy Trojan

About “TrojanSpy:Win32/Nivdort.DC” infection

Malware Removal

The TrojanSpy:Win32/Nivdort.DC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Nivdort.DC virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine TrojanSpy:Win32/Nivdort.DC?


File Info:

name: C2A2CF848B2A6F82B24B.mlw
path: /opt/CAPEv2/storage/binaries/23e3d5791390b70c614fd666fc28f4f78f5cd6cd860ee2174085fe15d01cf40c
crc32: EFE9F396
md5: c2a2cf848b2a6f82b24b8617fef1825a
sha1: 0e85acf0c3d801caadf873601c4179e535ce9b61
sha256: 23e3d5791390b70c614fd666fc28f4f78f5cd6cd860ee2174085fe15d01cf40c
sha512: 9771c282f4b489d1f8cb01e34fd95a234d4dc45bc1a940fbfca4d36700d73157e2d6a0cd4c577874dbe91b240bc0c72275fe12a551c48e81f6c53b911c91b087
ssdeep: 6144:bl0WGhgvqmkMS+JD5TkvmEXJ7FvMGfGYjxA:blrGhKC+JDiJ7Cu9A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10234AD26DA110623DC4165FD826C3BB2EA6EA2B87B1865C343D632D418F07D9E63774F
sha3_384: 3f10bf3577865b315e3f0316561c6bcb7858222278dae1e20733f93e44ae7b270bfec9ee3a6755639b6f33afd3c06e3d
ep_bytes: 66a198dc44000fbfc869c982d4d1f081
timestamp: 2014-10-25 12:02:38

Version Info:

0: [No Data]

TrojanSpy:Win32/Nivdort.DC also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Kelios.1
FireEyeGeneric.mg.c2a2cf848b2a6f82
CAT-QuickHealTrojanSpy.Nivdort.DR3
McAfeeTrojan-FHRG!C2A2CF848B2A
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004dc2a31 )
K7GWTrojan ( 004dc2a31 )
Cybereasonmalicious.0c3d80
BaiduWin32.Trojan.Generic.bd
CyrenW32/Nivdort.H.gen!Eldorado
SymantecTrojan.Bayrob!gen6
ESET-NOD32a variant of Win32/Bayrob.AT.gen
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Kelios.1
AvastWin32:Vupa [Cryp]
EmsisoftGen:Heur.Kelios.1 (B)
F-SecureHeuristic.HEUR/AGEN.1318579
DrWebTrojan.DownLoader46.11695
VIPREGen:Heur.Kelios.1
TrendMicroTROJ_BAYROB.SM7
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
SophosMal/Bayrob-A
IkarusTrojan.Win32.Bayrob
AviraHEUR/AGEN.1318579
MicrosoftTrojanSpy:Win32/Nivdort.DC
ArcabitTrojan.Kelios.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Kelios.1
GoogleDetected
AhnLab-V3Trojan/Win32.Xema.C1317897
BitDefenderThetaAI:Packer.E86525A11E
ALYacGen:Heur.Kelios.1
MAXmalware (ai score=83)
VBA32BScope.TrojanSpy.Nivdort
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_BAYROB.SM7
RisingTrojan.Generic@AI.100 (RDML:C02nqAbn5no8Suj2C6wA+Q)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bayrob.AQ!tr
AVGWin32:Vupa [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanSpy:Win32/Nivdort.DC?

TrojanSpy:Win32/Nivdort.DC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment