Spy Trojan

Should I remove “TrojanSpy:Win32/Nivdort.EP”?

Malware Removal

The TrojanSpy:Win32/Nivdort.EP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Nivdort.EP virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (96 unique times)
  • Starts servers listening on 127.0.0.1:13174, 127.0.0.1:15377
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself

How to determine TrojanSpy:Win32/Nivdort.EP?


File Info:

crc32: 64A2BC51
md5: 70b86057804c9cd33ec29630a55457de
name: 70B86057804C9CD33EC29630A55457DE.mlw
sha1: 902d720864067669223d2d6a7d1ed338a8b8c8fb
sha256: 9e451c001989b5c02e174c7dbb8adc43d52b5f4fa185684c4dadbfcd535953fe
sha512: a1981a5579b6ab5c713de06f65ac8e89f6066417f0af00a1285bef6a3733a9f18051fe1c79da63eeaa6330d058b7ac4d4d1ba8c4c1751b100c853980696db044
ssdeep: 49152:BjA0NKZ3RbSxCAkKfy/7V9xRo5jYS4N+nhEGz:5AZZ3RbbK6DV9xRo5kS44
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Nivdort.EP also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CAT-QuickHealTrojanSpy.Nivdort.DR3
ALYacGen:Variant.Zusy.189044
CylanceUnsafe
ZillyaTrojan.Bayrob.Win32.27522
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 004f437d1 )
K7AntiVirusTrojan ( 004f437d1 )
BaiduWin32.Trojan.Bayrob.d
CyrenW32/S-0a21c3d0!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Bayrob.CS
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.189044
NANO-AntivirusTrojan.Win32.Bayrob.ehwycs
MicroWorld-eScanGen:Variant.Zusy.189044
TencentWin32.Trojan.Generic.Aguy
Ad-AwareGen:Variant.Zusy.189044
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.1nW@aOHBljf
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_BAYROB.SM7
McAfee-GW-EditionBehavesLike.Win32.VirRansom.th
FireEyeGeneric.mg.70b86057804c9cd3
EmsisoftGen:Variant.Zusy.189044 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.amxhr
AviraHEUR/AGEN.1118508
eGambitUnsafe.AI_Score_92%
Antiy-AVLTrojan/Generic.ASMalwS.1C1E42E
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanSpy:Win32/Nivdort.EP
GDataGen:Variant.Zusy.189044
AhnLab-V3Trojan/Win32.Bayrob.C1584240
Acronissuspicious
McAfeeGenericRXGJ-VD!70B86057804C
MAXmalware (ai score=80)
VBA32BScope.Trojan.Nivdort
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_BAYROB.SM7
RisingTrojan.Generic@ML.100 (RDML:rVpa6tl+NHqDULNPEdWBow)
YandexTrojan.GenAsa!9jdu9WeLfrg
IkarusTrojan.Win32.Bayrob
FortinetW32/Generic.AP.41D3E!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove TrojanSpy:Win32/Nivdort.EP?

TrojanSpy:Win32/Nivdort.EP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment