Worm

Should I remove “Worm:Win32/Nuqel.BE”?

Malware Removal

The Worm:Win32/Nuqel.BE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Nuqel.BE virus can do?

  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Worm:Win32/Nuqel.BE?


File Info:

crc32: 775E8677
md5: 9dc49d92855dc60cd6e0205a8a8a9a00
name: 9DC49D92855DC60CD6E0205A8A8A9A00.mlw
sha1: 3055f05e8d7b2531bf0d833205228aff562b459c
sha256: bcaa5a546fa5e89d14965d2c039b1affa444de2b5df2939e3d0e263f76ae744a
sha512: dedab2078f9febee1e8d6a5ba436845803d1d5d080fae8dae92fb782c8baa99c9eb6789f939cfb4bd64ddc2ca44034fb30a19282651ac29fc67f8e0ad7fa8355
ssdeep: 6144:fYZTNk3D6LyUXwLLk+cR3qh0GQ43VJRD0ew+/UO85jXdeq1Yq:fSNC80I+cR3R03VseuO850
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

CompiledScript: AutoIt v3 Script : 3, 2, 12, 0
FileVersion: 3, 2, 12, 0
FileDescription:
Translation: 0x0809 0x04b0

Worm:Win32/Nuqel.BE also known as:

BkavW32.FuerboosBM.Trojan
K7AntiVirusTrojan ( 003fb7871 )
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner1.54163
CynetMalicious (score: 100)
CAT-QuickHealWorm.Sohanad.AQ4
ALYacGen:Trojan.Heur.BmLfrn1K@Vlib
CylanceUnsafe
ZillyaWorm.AutoitGen.Win32.1063
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 003fb7871 )
Cybereasonmalicious.2855dc
BaiduWin32.Worm.Generic.d
CyrenW32/Trojan.GPWQ-0777
SymantecW32.Imaut.E
ESET-NOD32Win32/Autoit.FJ
ZonerTrojan.Win32.Autoit.31053
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Worm.Autorun-313
KasperskyWorm.Win32.AutoIt.dn
BitDefenderGen:Trojan.Heur.BmLfrn1K@Vlib
NANO-AntivirusTrojan.Script.AutoIt.dcpaxn
ViRobotWorm.Win32.AutoIt.265927
MicroWorld-eScanGen:Trojan.Heur.BmLfrn1K@Vlib
Ad-AwareGen:Trojan.Heur.BmLfrn1K@Vlib
SophosMal/Generic-R + Mal/Sohana-A
ComodoVirus.Win32.Virut.CE@1fhkga
BitDefenderThetaAI:Packer.4F03E64F1D
VIPREVirus.Win32.Sality.atbh (v)
TrendMicroWORM_SOHANAD.ILA
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
FireEyeGeneric.mg.9dc49d92855dc60c
EmsisoftGen:Trojan.Heur.BmLfrn1K@Vlib (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/HLLP.Kuku.poly2
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASCommon.11C
KingsoftWin32.Heur.KVM007.a.(kcloud)
MicrosoftWorm:Win32/Nuqel.BE
ArcabitTrojan.Heur.EA38B7
AegisLabWorm.Win32.AutoIt.mC7K
GDataWin32.Virus.Sality.A
AhnLab-V3HEUR/Fakon.mwf.X1381
Acronissuspicious
McAfeeW32/YahLover.worm.gen.b
MAXmalware (ai score=86)
VBA32Worm.AutoIt
MalwarebytesSality.Virus.FileInfector.DDS
PandaTrj/CI.A
TrendMicro-HouseCallWORM_SOHANAD.ILA
RisingTrojan.DL.Win32.Undef.cqz (CLASSIC)
YandexTrojan.DR.Agent.OIDA
IkarusWorm.Win32.AutoIt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoIt.FJ!worm
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove Worm:Win32/Nuqel.BE?

Worm:Win32/Nuqel.BE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment