Worm

Should I remove “Worm:Win32/Nuqel.TB”?

Malware Removal

The Worm:Win32/Nuqel.TB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Nuqel.TB virus can do?

  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

h1.ripway.com
www.balu000.0catch.com
www.balu001.0catch.com
www.balu002.0catch.com
www.balu003.0catch.com
www.balu004.0catch.com
www.balu005.0catch.com
www.balu006.0catch.com
www.balu007.0catch.com
www.balu008.0catch.com
www.balu009.0catch.com
www.balu010.0catch.com
www.balu011.0catch.com
www.balu012.0catch.com
www.balu013.0catch.com

How to determine Worm:Win32/Nuqel.TB?


File Info:

crc32: 8F620942
md5: 0cb34c247f1ec950c81c3ca9a84defd2
name: 0CB34C247F1EC950C81C3CA9A84DEFD2.mlw
sha1: f6f60325a8a2061d6a08e1589a6b36497913434d
sha256: 10f20158f5a957551e63be8fda63982d3655892fd380081462e6bb5166299c35
sha512: e391e3267ed99011eed2409eeaa7768afa2cda6609662577195d5118a36e6e279811e9e7ed5b31d9587a941ad6e30146e7360b5fabb42c94b72fe52a80eceb31
ssdeep: 6144:Ppqoa8aLiC/2OLaAN7gNVpNleQUohBfGPOtQciXeL/XYqGlebojSP2pjNhcAYnC:PpqiC/2OeAtkCP4cejGSOpRK3C1SSr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
Company: Microsoft Corporation
Product Name: Microsoftxae Windowsxae Operating System
Product Version: 6.00.2900.2180
Original File name: System32.exe
Internal Name: System32
Translation: 0x0809 0x04b0

Worm:Win32/Nuqel.TB also known as:

K7AntiVirusEmailWorm ( 0008b4a71 )
LionicW32.W.AutoRun.llU2
TotalDefenseWin32/FakeFLDR_i
MicroWorld-eScanGen:Trojan.Heur.AutoIT.15
CAT-QuickHealWorm.Tupym.A5
CylanceUnsafe
ZillyaWorm.Autorun.Win32.79560
CrowdStrikemalicious_confidence_100% (D)
K7GWEmailWorm ( 0008b4a71 )
Cybereasonmalicious.1b8fb7
TrendMicroWORM_SOHAND.SM
BaiduWin32.Trojan.AutoIt.a
CyrenW32/AutoIt.AG.gen!Eldorado
SymantecW32.Imaut!gen1
ESET-NOD32Win32/Autoit.EB
AvastAutoIt:AutoRun-B@BC [Wrm]
ClamAVWin.Worm.Autorun-313
GDataWin32.Worm.Autorun.A@gen
KasperskyWorm.Win32.AutoRun.fnc
BitDefenderGen:Trojan.Heur.AutoIT.15
NANO-AntivirusTrojan.Script.Autorun.ddaffd
TencentWorm.Win32.Autorun.fnc
Ad-AwareGen:Trojan.Heur.AutoIT.15
SophosW32/AutoRun-BUC
F-SecureGen:Trojan.Heur.AutoIT.15
DrWebTrojan.StartPage.31354
VIPREWorm.Win32.Tupym.A (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Tupym.dm
EmsisoftGen:Trojan.Heur.AutoIT.15 (B)
SentinelOnestatic engine – malicious
F-ProtW32/AutoIt.AG.gen!Eldorado
Endgamemalicious (high confidence)
AviraTR/Patched.Ren.Gen
MicrosoftWorm:Win32/Nuqel.TB
JiangminTrojan.Generic.adpae
ArcabitTrojan.Heur.AutoIT.15
SUPERAntiSpywareTrojan.Agent/Gen-Virut
ZoneAlarmWorm.Win32.AutoRun.fnc
AhnLab-V3HEUR/Fakon.mwf
McAfeeW32/Tupym.worm
AVwareWorm.Win32.Tupym.A (v)
MAXmalware (ai score=85)
VBA32Trojan-Downloader.Autoit.gen
MalwarebytesWorm.AutoRun.FLD
PandaTrj/Autoit.gen
TrendMicro-HouseCallWORM_SOHAND.SM
RisingWorm.VobfusEx!1.99DF (CLASSIC)
YandexTrojan.Autorun!VgV/xk+eV94
IkarusWorm.Win32.AutoRun
FortinetW32/AutoVt.AAAD!tr
AVGAutoIt:AutoRun-B@BC [Wrm]
Qihoo-360Malware.Radar01.Gen

How to remove Worm:Win32/Nuqel.TB?

Worm:Win32/Nuqel.TB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment