Worm

Worm:Win32/Niojec information

Malware Removal

The Worm:Win32/Niojec is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Niojec virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Niojec?


File Info:

name: 34B84C8CEF4A522881E3.mlw
path: /opt/CAPEv2/storage/binaries/fc62f285bec7f55ddbc81c54a9c463ea48b05a88fdba12155093b22d84489b07
crc32: 087210AE
md5: 34b84c8cef4a522881e39da0cd344520
sha1: 7af9e69f498d3dbbe7e3678249283b1fad8c44ec
sha256: fc62f285bec7f55ddbc81c54a9c463ea48b05a88fdba12155093b22d84489b07
sha512: ad9da021ae68495b47f41dcaef27660c49dc30e1fcd45010e381f5ae7b55f187de289c09669a7d410796e66aa17451abb860265eaead4aba1313bac8fa78bcea
ssdeep: 1536:cOYEou5tJkkXQyWaMGLzLsxNkdEMOb2F2:5YVuikgyWF0vsXkdEMcc2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16363A313BF105129F682C9B52CA58165FD56BE764690ACDBB385AFC93832183F6F070B
sha3_384: 2d9c88a8cf7a0a3a537f48b5d8f48435f33163eeaa7cbb5d60b133c2c75e5b2ef6df920525f630e0601bdd494a2fb1ec
ep_bytes: 68e81c4000e8f0ffffff000000000000
timestamp: 2008-01-24 12:30:18

Version Info:

Translation: 0x0804 0x04b0
CompanyName: Microsoft Corporation
FileDescription: Services and Controller app
LegalCopyright: (C) Microsoft Corporation. All rights reserved.
ProductName: Microsoft(R) Windows(R) Operating System
FileVersion: 5.01.2201
ProductVersion: 5.01.2201
InternalName: secpol
OriginalFilename: secpol.exe

Worm:Win32/Niojec also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
DrWebWin32.HLLW.Autoruner.1396
MicroWorld-eScanGeneric.Malware.B!dld!.1E57100F
FireEyeGeneric.mg.34b84c8cef4a5228
SkyhighBehavesLike.Win32.Vilsel.km
ALYacGeneric.Malware.B!dld!.1E57100F
ZillyaDownloader.VB.Win32.93809
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanDownloader:Win32/Niojec.094b5b35
K7GWTrojan ( 004bcce41 )
BitDefenderThetaAI:Packer.E5A768FB1C
VirITTrojan.Win32.Generic.AUTG
SymantecW32.SillyFDC
ESET-NOD32a variant of Win32/TrojanDownloader.VB.NOY
APEXMalicious
TrendMicro-HouseCallWORM_AUTORUN.MCS
ClamAVWin.Trojan.VB-709
KasperskyTrojan-Downloader.Win32.VB.ckd
BitDefenderGeneric.Malware.B!dld!.1E57100F
NANO-AntivirusTrojan.Win32.VB.wrcy
AvastWin32:Evo-gen [Trj]
EmsisoftGeneric.Malware.B!dld!.1E57100F (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREGeneric.Malware.B!dld!.1E57100F
TrendMicroWORM_AUTORUN.MCS
Trapminemalicious.high.ml.score
SophosMal/VB-GI
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Downloader.K.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.VB
KingsoftWin32.Troj.Undef.a
MicrosoftWorm:Win32/Niojec.gen
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitGeneric.Malware.B!dld!.1E57100F
ZoneAlarmTrojan-Downloader.Win32.VB.ckd
GDataGeneric.Malware.B!dld!.1E57100F
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.VB.C7784
Acronissuspicious
McAfeeGenDownloader.s
MAXmalware (ai score=99)
VBA32BScope.Backdoor.Bifrose
Cylanceunsafe
PandaTrj/Wow.RJ
IkarusWorm.Win32.AutoRun
MaxSecureTrojan.Malware.1327631.susgen
FortinetW32/VB.INK!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/VB.NOY

How to remove Worm:Win32/Niojec?

Worm:Win32/Niojec removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment