Worm

Worm.Nuj.B8 removal guide

Malware Removal

The Worm.Nuj.B8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Nuj.B8 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.universal101.com

How to determine Worm.Nuj.B8?


File Info:

crc32: 6FC389D1
md5: aa70eeb02d2144be1b22c1659d5fa88d
name: AA70EEB02D2144BE1B22C1659D5FA88D.mlw
sha1: 05cd21654097426adf326dcd0f1636b4c5a99af9
sha256: 687c11cbe93c85822e1d5cd8e7f3967cfda809529187e196c0766b1636bf40fd
sha512: 1a586a2e113276f4cd2d95b01f01458585992d9ba2ff6daec27ab44e5dff710c0caf24056894f26a081f50662de949576f9027daaee4fa674d9d953d66b26e28
ssdeep: 49152:67N1ahC50V7N1ahC+0V7N1ahCK0V7N1ahCm0:67s7r7X7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Worm.Nuj.B8 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35681909
FireEyeGeneric.mg.aa70eeb02d2144be
CAT-QuickHealWorm.Nuj.B8
ALYacTrojan.GenericKD.35681909
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 0001b7311 )
BitDefenderTrojan.GenericKD.35681909
K7GWTrojan-Downloader ( 0001b7311 )
Cybereasonmalicious.02d214
CyrenW32/Oberal.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Small-MHA [Trj]
ClamAVWin.Malware.Alkt-6915258-0
KasperskyTrojan.Win32.Small.xxd
NANO-AntivirusTrojan.Win32.Small.cnwqmt
ViRobotTrojan.Win32.Banker.741376.C
RisingTrojan.Oberal!1.BDEF (CLASSIC)
Ad-AwareTrojan.GenericKD.35681909
EmsisoftTrojan.GenericKD.35681909 (B)
ComodoTrojWare.Win32.Small.~QW@gohe
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.LowZones.1991
TrendMicroTROJ_FAKEAV.SMNA
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
MaxSecureTrojan.Malware.121218.susgen
SophosML/PE-A + Mal/QLowZ-A
SentinelOneStatic AI – Malicious PE – Spyware
JiangminTrojanSpy.Banker.rpg
AviraTR/ATRAPS.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Small.xxd
MicrosoftPUA:Win32/KuaiZip
ArcabitTrojan.Generic.D2207675
ZoneAlarmTrojan.Win32.Small.xxd
GDataWin32.Trojan.FakeAV.Q
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R73886
Acronissuspicious
McAfeegeneric!bg.yb
TACHYONTrojan/W32.DP-Downloader.Zen
VBA32TScope.Trojan.Delf
MalwarebytesPUP.Optional.Kuauzip.DDS
PandaTrj/Banker.FWD
ESET-NOD32a variant of Win32/TrojanDownloader.FakeAlert.VA
TrendMicro-HouseCallTROJ_FAKEAV.SMNA
TencentTrojan.Win32.Small.b
YandexTrojan.GenAsa!RZ0bt4DpWOE
IkarusTrojan-Banker.Win32.Banker
eGambitUnsafe.AI_Score_99%
FortinetW32/Banker.ACSI!tr
BitDefenderThetaAI:Packer.14C16B3A19
AVGWin32:Small-MHA [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360QVM41.1.Malware.Gen

How to remove Worm.Nuj.B8?

Worm.Nuj.B8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment