Malware

About “Win32/Nimda.E” infection

Malware Removal

The Win32/Nimda.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Nimda.E virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Nimda.E?


File Info:

name: B7931336CC48D89426C6.mlw
path: /opt/CAPEv2/storage/binaries/8f0fa97f6702d5dc5888ce3ab9fc96a0b5c7e8520bcab5ac07ae28788be637ed
crc32: 64D39764
md5: b7931336cc48d89426c652c701221ab6
sha1: 4032b79dbe6938074125da2e80d7063fd2130dcb
sha256: 8f0fa97f6702d5dc5888ce3ab9fc96a0b5c7e8520bcab5ac07ae28788be637ed
sha512: 04e7d473eabe8cf7dcde0021f5829aca56e1643b5b33ac936090f3ce245e6a24e4a7cc7604106cf064ddd34f5a1e19e6efc40027d2258a05ba98b8fc945208e5
ssdeep: 24576:PJ8crWBTe8nohs1lOYLI8ZRSKQu3Becpvw8sz2kyUHNfpmzLFXyJnh1QJB7/ufq2:P6GPHNozLFcX87/HG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116B57C45E682C0FAD8AA163151AB2BB72C359F31151DE9D3D3C82C257D72BA0F22937D
sha3_384: e16c1cac2421922ecc287b3eb14eb214bf57c4480b0bb8cbdb3116767c0c3608c3c6502708ddef57b3a1fd03e8935802
ep_bytes: 558bec83ec445657ff15481000308b3d
timestamp: 2000-01-21 08:15:51

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office 2000 component
FileVersion: 9.0.3720
InternalName: Osa
LegalCopyright: Copyright© Microsoft Corporation 1994-1999. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: Osa.Exe
ProductName: Microsoft Office 2000
ProductVersion: 9.0.3720
Translation: 0x0000 0x04e4

Win32/Nimda.E also known as:

LionicWorm.Win32.Nimda.p!c
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Nimda.57344
FireEyeGeneric.mg.b7931336cc48d894
McAfeeArtemis!B7931336CC48
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWorm.Win32.Nimda.e
K7AntiVirusTrojan ( 0055343f1 )
AlibabaWorm:Win32/Nimda.35911ae3
K7GWTrojan ( 0055343f1 )
Cybereasonmalicious.dbe693
CyrenW32/NetWorm.YYMQ-0484
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Nimda.E
APEXMalicious
ClamAVWin.Worm.N-74
KasperskyNet-Worm.Win32.Nimda.e
NANO-AntivirusTrojan.Win32.Nimda.glkx
AvastWin32:Nimda-E@Eml
TencentMalware.Win32.Gencirc.10b0bbd8
TrendMicroPE_NIMDA.E
McAfee-GW-EditionW32/Nimda.gen@MM
SophosMal/Generic-R
AviraW32/Nimda.3
Antiy-AVLTrojan/Generic.ASBOL.881
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
VBA32Win32.HLLW.Nimda.49200
MalwarebytesMalware.AI.3370218431
TrendMicro-HouseCallPE_NIMDA.E
RisingWorm.Nimda.ea (CLASSIC)
YandexTrojan.GenAsa!F3AK7Eo1MxM
IkarusTrojan.I-Worm.Nimda
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Nimda.E!worm.im
AVGWin32:Nimda-E@Eml
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/Nimda.E?

Win32/Nimda.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment