Spy Trojan

What is “TrojanSpy:Win32/Nivdort.DE”?

Malware Removal

The TrojanSpy:Win32/Nivdort.DE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Nivdort.DE virus can do?

  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
crowdanother.net
summerbusiness.net
crowdbusiness.net
summerappear.net
crowdappear.net
thoughtmanner.net
watermanner.net
thoughtanother.net
wateranother.net
thoughtbusiness.net
waterbusiness.net
thoughtappear.net
waterappear.net
womanmanner.net
smokemanner.net
womananother.net
smokeanother.net
womanbusiness.net
smokebusiness.net
womanappear.net
smokeappear.net
partymanner.net
fightmanner.net
partyanother.net
fightanother.net
partybusiness.net
fightbusiness.net
partyappear.net
fightappear.net
freshinstead.net
experienceinstead.net
freshexplain.net
experienceexplain.net
freshbright.net
experiencebright.net
freshinside.net
experienceinside.net
gentlemaninstead.net
alreadyinstead.net
gentlemanexplain.net
alreadyexplain.net
gentlemanbright.net
alreadybright.net
gentlemaninside.net
alreadyinside.net
followinstead.net
memberinstead.net
followexplain.net
memberexplain.net
followbright.net
memberbright.net
followinside.net
memberinside.net
begininstead.net
knowninstead.net
beginexplain.net
knownexplain.net
beginbright.net
knownbright.net
begininside.net
knowninside.net
summerinstead.net
crowdinstead.net
summerexplain.net
crowdexplain.net
summerbright.net
crowdbright.net
summerinside.net
crowdinside.net
thoughtinstead.net
waterinstead.net
thoughtexplain.net
waterexplain.net
thoughtbright.net
waterbright.net
thoughtinside.net
waterinside.net
womaninstead.net
smokeinstead.net
womanexplain.net
smokeexplain.net
womanbright.net
smokebright.net
womaninside.net
smokeinside.net
partyinstead.net
fightinstead.net
partyexplain.net
fightexplain.net
partybright.net
fightbright.net
partyinside.net
fightinside.net
freshready.net
experienceready.net
freshbrown.net
experiencebrown.net
freshpeople.net
experiencepeople.net
freshdaughter.net
experiencedaughter.net
gentlemanready.net
alreadyready.net
gentlemanbrown.net
alreadybrown.net
gentlemanpeople.net
alreadypeople.net
gentlemandaughter.net
alreadydaughter.net
followready.net
memberready.net
followbrown.net
memberbrown.net
followpeople.net
memberpeople.net
followdaughter.net
memberdaughter.net
beginready.net
knownready.net
beginbrown.net
knownbrown.net
beginpeople.net
knownpeople.net
begindaughter.net
knowndaughter.net
summerready.net
crowdready.net
summerbrown.net
crowdbrown.net
summerpeople.net
crowdpeople.net
summerdaughter.net
crowddaughter.net
thoughtready.net
waterready.net
thoughtbrown.net
waterbrown.net
thoughtpeople.net
waterpeople.net
thoughtdaughter.net
waterdaughter.net
womanready.net
smokeready.net
womanbrown.net
smokebrown.net
womanpeople.net
smokepeople.net
womandaughter.net
smokedaughter.net
partyready.net
fightready.net
partybrown.net
fightbrown.net
partypeople.net
fightpeople.net
partydaughter.net
fightdaughter.net
freshnation.net
experiencenation.net
freshsoldier.net
experiencesoldier.net
freshplease.net
experienceplease.net
freshcondition.net
experiencecondition.net
gentlemannation.net
alreadynation.net
gentlemansoldier.net
alreadysoldier.net
gentlemanplease.net

How to determine TrojanSpy:Win32/Nivdort.DE?


File Info:

crc32: EA83004C
md5: fd4dc24924b3e1d15bb78a854984469e
name: FD4DC24924B3E1D15BB78A854984469E.mlw
sha1: 5a2455ec79d37f32eff74cf53a7888b4cd999165
sha256: 10e707bb2453baa82bcef7a2a82fa139b5c6805735227b4dbb7885a2ebde1a96
sha512: c98d104b4b1de032a70c2593f01cf2842f359c45e5fff8a287540dee0a248a68edbcbae7007ce1157dbd423124dc7aee60bb3131e8e0560db9507f8289e49f0c
ssdeep: 12288:MzIffumcGv8bZuugtaTslkSiuK4IfIdptg6QtxdIEeUtatQ:MkfEG8lDQlkyKfIEeUtatQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Nivdort.DE also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004da8bd1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojanSpy.Nivdort.DR3
ALYacGen:Variant.Razy.11645
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Nivdort.b4547e4f
K7GWTrojan ( 004d977f1 )
Cybereasonmalicious.924b3e
BaiduWin32.Trojan.Generic.bd
CyrenW32/Trojan.GG.gen!Eldorado
SymantecTrojan.Bayrob!gen6
ESET-NOD32a variant of Win32/Bayrob.AK
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyHEUR:Trojan.Win32.Bayrob.pef
BitDefenderGen:Variant.Razy.11645
NANO-AntivirusTrojan.Win32.Dwn.dzjdph
MicroWorld-eScanGen:Variant.Razy.11645
Ad-AwareGen:Variant.Razy.11645
SophosML/PE-A + Troj/Nivdort-BV
BitDefenderThetaAI:Packer.2EE6429C1E
TrendMicroTROJ_BAYROB.SM3
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
FireEyeGeneric.mg.fd4dc24924b3e1d1
EmsisoftGen:Variant.Razy.11645 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1111157
eGambitUnsafe.AI_Score_98%
MicrosoftTrojanSpy:Win32/Nivdort.DE
ZoneAlarmHEUR:Trojan.Win32.Bayrob.pef
GDataGen:Variant.Razy.11645
AhnLab-V3Trojan/Win32.Blocker.C1313903
McAfeeTrojan-FHOH!FD4DC24924B3
MAXmalware (ai score=88)
VBA32BScope.TrojanSpy.Nivdort
MalwarebytesTrojan.Bayrob.Generic
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_BAYROB.SM3
RisingTrojan.Generic@ML.100 (RDML:+yzTsok0lUroVRBRD21+yw)
IkarusTrojan.Bayrob
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bayrob.AQ!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove TrojanSpy:Win32/Nivdort.DE?

TrojanSpy:Win32/Nivdort.DE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment