Malware

W32.Nimnul.F4 removal

Malware Removal

The W32.Nimnul.F4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32.Nimnul.F4 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
ddos.dnsnb8.net

How to determine W32.Nimnul.F4?


File Info:

crc32: CF5EF1E3
md5: c4f44ebad69309421f00f0cbdf93dded
name: C4F44EBAD69309421F00F0CBDF93DDED.mlw
sha1: 041cd19248eade722757b7a8487cf5c0b7d6c89b
sha256: dcf02889e710eba4da9e7c351bb9f72dbba08e9e8323a02b72df2d8dec4b0d47
sha512: e3c9c113b360315a9d90f0ccd0a552806679ef1bea9b9790aff0b8c3ed93adb5a1d46de1faeedce2e909acee7a5baa3d3831ded352654909434362ab9587473e
ssdeep: 384:kXZQaD7U8iu4YsAa7ZA0UvH2lsRv21yW7GbAxur6+Y9PffPz:EQGPL4vzZq2o9W7GsxBbPr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

W32.Nimnul.F4 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebBackDoor.Darkshell.246
CynetMalicious (score: 100)
CAT-QuickHealW32.Nimnul.F4
ALYacTrojan.Downloader.JQJR
CylanceUnsafe
ZillyaDownloader.Banload.Win32.56343
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Alibabavirus:Win32/InfectPE.ali2000007
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ad6930
CyrenW32/Downloader.WXUE-4498
SymantecW32.Wapomi.C!inf
ESET-NOD32Win32/Wapomi.BA
ZonerVirus.Win32.21902
APEXMalicious
TotalDefenseWin32/Tnega.FSQNIcB
AvastWin32:Malware-gen
ClamAVWin.Trojan.Downloader-64720
KasperskyTrojan.Win32.Agent.xadzcq
BitDefenderTrojan.Downloader.JQJR
NANO-AntivirusTrojan.Win32.Banload.cstqaj
MicroWorld-eScanTrojan.Downloader.JQJR
TencentTrojan.Win32.Small.aab
Ad-AwareTrojan.Downloader.JQJR
SophosMal/Generic-R + W32/Nimnul-A
ComodoTrojWare.Win32.Trojan.XPack.~gen1@1rwlif
BitDefenderThetaAI:Packer.659502481E
VIPRETrojan.Win32.Small.z (v)
TrendMicroMal_DLDER
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
FireEyeGeneric.mg.c4f44ebad6930942
EmsisoftTrojan.Downloader.JQJR (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Banload.bpxt
AviraTR/Dldr.Small.Z.haljq
eGambitUnsafe.AI_Score_99%
KingsoftHeur.SSC.2205964.0010.(kcloud)
MicrosoftTrojanDownloader:Win32/Small.gen!Z
GridinsoftTrojan.Win32.Downloader.zv!s1
ZoneAlarmTrojan.Win32.Agent.xadzcq
GDataTrojan.Downloader.JQJR
AhnLab-V3Trojan/Win32.Agent.R94615
Acronissuspicious
McAfeeArtemis!C4F44EBAD693
MAXmalware (ai score=81)
VBA32TrojanDownloader.Banload
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_DLDER
RisingWin32.Wapomi.a (CLOUD)
YandexBackDoor.Darkshell!bbpw5cNU8q4
IkarusWin32.Jadtre
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Nimnul.F
AVGWin32:Malware-gen
Qihoo-360Win32/TrojanDownloader.Small.Hw0AvGIA

How to remove W32.Nimnul.F4?

W32.Nimnul.F4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment