Malware

Win32/Nuwar.M removal guide

Malware Removal

The Win32/Nuwar.M is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Nuwar.M virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Nuwar.M?


File Info:

name: 75A533DB3994D08ABAC4.mlw
path: /opt/CAPEv2/storage/binaries/a375906478460b918ddf46bc3af3a4cd2fab28d3f9fe672c15cd72f0a9ae59c4
crc32: DF2BB34D
md5: 75a533db3994d08abac45b7123b0c1d2
sha1: 7094d5605a54874750b73af6be1e1a2176594674
sha256: a375906478460b918ddf46bc3af3a4cd2fab28d3f9fe672c15cd72f0a9ae59c4
sha512: d696c3c1869fc5dc2e71e9c97c2c21bc88b7601ea0aaafbd6fd2e55152c6481e1a307b2db23e53f22b81c4bf070b720f943e4332d47ab74988172ac93f833555
ssdeep: 192:7O7ho5Fr7fnMTJRywXayRcEcY7RZRDZ4VX4:7O7mzeJtayR3c+D4Vo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DD1E5834D022434D758E23ADEB9AB3F8CB7C13C2CC6BDE18F184A665E0C8B5816497D
sha3_384: 999803f3f5e23269b969824d9fd9ed3222585635d157dffeba14d1d08e7261766fb001cf891b97aae3016b32d8ee3f69
ep_bytes: e800000000b8f57740006a006a00ff10
timestamp: 2005-12-13 14:55:50

Version Info:

0: [No Data]

Win32/Nuwar.M also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Small.kYKt
Elasticmalicious (moderate confidence)
DrWebTrojan.DownLoader.6811
MicroWorld-eScanTrojan.Peed.Gen
FireEyeGeneric.mg.75a533db3994d08a
CAT-QuickHealI-Worm.Ludar.a
SkyhighBehavesLike.Win32.Generic.xc
McAfeeTibs
MalwarebytesGeneric.Malware/Suspicious
ZillyaWorm.Luder.Win32.7
SangforWorm.Win32.Luder.a
K7AntiVirusTrojan ( 000116411 )
AlibabaWorm:Win32/Luder.813624ad
K7GWTrojan ( 000116411 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Peed.Gen
BitDefenderThetaAI:Packer.95EC91AA1E
VirITTrojan.Win32.DownLoader.KBZ
SymantecTrojan.Packed.8
ESET-NOD32Win32/Nuwar.M
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.389-1
KasperskyEmail-Worm.Win32.Luder.a
BitDefenderTrojan.Peed.Gen
NANO-AntivirusTrojan.Win32.Luder.cfbwv
SUPERAntiSpywareTrojan.Unknown Origin
AvastWin32:Glowa-Y [Wrm]
TencentWin32.Worm-Email.Luder.Fflw
EmsisoftTrojan.Peed.Gen (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
VIPRETrojan.Peed.Gen
TrendMicroTROJ_MULP.P
Trapminemalicious.high.ml.score
SophosW32/Dref-V
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Tibs.rg
WebrootWorm:Win32/Nuwar.F@mm
VaristW32/Downloader.VDFU-5428
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
Antiy-AVLWorm[Email]/Win32.Luder.a
KingsoftWin32.HeurC.KVMH008.a
XcitiumTrojWare.Win32.TrojanDownloader.Small.AVT@2dg9
MicrosoftTrojan:Win32/Vxidl.gen!B
ViRobotI-Worm.Win32.Glowa.Gen
ZoneAlarmEmail-Worm.Win32.Luder.a
GDataTrojan.Peed.Gen
GoogleDetected
AhnLab-V3Win32/Glowa.worm.B
VBA32Trojan-Downloader.Revelation.Tibs.B
TACHYONWorm/W32.Nuwar.6295
Cylanceunsafe
PandaW32/Luder.A.worm
TrendMicro-HouseCallTROJ_MULP.P
RisingWorm.Mail.PostCard.b (CLASSIC)
YandexTrojan.GenAsa!ZlBJ4uedsRM
IkarusTrojan-Downloader.Win32.Tibs.jy
MaxSecureVirus.W32.Luder.A
FortinetW32/Tibs.gen
AVGWin32:Glowa-Y [Wrm]
DeepInstinctMALICIOUS

How to remove Win32/Nuwar.M?

Win32/Nuwar.M removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment