In this message, I am going to clarify how the Nimda trojan infused into your personal computer, and the best way to get rid of Nimda trojan virus.
What is Nimda trojan?
Name | Nimda |
Infection Type | Trojan |
Symptoms |
|
Similar behavior | Guag, BlueTraveller, Zoxpng, Pyramid, Daserf, MagicHound |
Fix Tool | See If Your System Has Been Affected by Nimda trojan |
Trojan viruses are among the leading malware kinds by its injection frequency for quite a long period of time. And now, during the pandemic, when malware got enormously active, trojan viruses enhanced their activity, too. You can see a number of messages on diverse resources, where users are complaining about the Nimda trojan virus in their computers, and also requesting for aid with Nimda trojan virus removal.
Trojan Nimda is a sort of virus that injects into your computer, and after that executes various destructive features. These features rely on a kind of Nimda trojan: it may serve as a downloader for other malware or as a launcher for another malicious program which is downloaded together with the Nimda trojan. Over the last 2 years, trojans are also delivered using e-mail attachments, and in the majority of situations utilized for phishing or ransomware infiltration.
Nimda2 also known as
Bkav | W32.AIDetect.malware2 |
Lionic | Trojan.Win32.FrauDrop.lqmD |
MicroWorld-eScan | Win32.Worm.Nimda.O |
ClamAV | Win.Trojan.Fakeav-3103 |
FireEye | Generic.mg.1f2a27639c98b58e |
CAT-QuickHeal | Trojan.FakeAV |
ALYac | Win32.Worm.Nimda.O |
Cylance | Unsafe |
VIPRE | Win32.Worm.Nimda.O |
Sangfor | Worm.Win32-Script.Save.Nimda |
K7AntiVirus | Trojan ( 0008d46e1 ) |
Alibaba | Trojan:Win32/Nimda.258cb23e |
K7GW | Trojan ( 0008d46e1 ) |
Cybereason | malicious.39c98b |
VirIT | Trojan.Win32.Zlob.AYMK |
Cyren | W32/FakeAlert.PQ.gen!Eldorado |
Symantec | Packed.Generic.332 |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/Kryptik.OCL |
APEX | Malicious |
Paloalto | generic.ml |
Cynet | Malicious (score: 99) |
Kaspersky | HEUR:Trojan.Win32.Generic |
BitDefender | Win32.Worm.Nimda.O |
NANO-Antivirus | Trojan.Win32.Small.dprph |
Avast | Win32:FakeAlert-AKX [Trj] |
Ad-Aware | Win32.Worm.Nimda.O |
TACHYON | Trojan-Spy/W32.ZBot.32912 |
Sophos | ML/PE-A + Mal/FakeAV-EA |
Comodo | TrojWare.Win32.Spy.Spyeyes.JNC@4ldfst |
DrWeb | Trojan.MulDrop2.5376 |
Zillya | Trojan.FakeAV.Win32.74841 |
TrendMicro | TROJ_FAKEAV.SM37 |
McAfee-GW-Edition | Generic FakeAV.nn |
Emsisoft | Win32.Worm.Nimda.O (B) |
SentinelOne | Static AI – Malicious PE |
GData | Win32.Worm.Nimda.O |
Jiangmin | TrojanSpy.Zbot.bavz |
Webroot | W32.Infostealer.Banker |
Avira | W32/Chir.B |
Antiy-AVL | Trojan[Spy]/Win32.Zbot |
Arcabit | Win32.Worm.Nimda.O |
ViRobot | Trojan.Win32.Downloader.31232.FK |
Microsoft | Trojan:JS/Nimda.A |
Detected | |
AhnLab-V3 | Trojan/Win32.ADH.R23248 |
McAfee | Generic FakeAV.nn |
MAX | malware (ai score=100) |
VBA32 | TrojanSpy.Zbot |
Malwarebytes | Trojan.Zbot |
TrendMicro-HouseCall | TROJ_FAKEAV.SM37 |
Rising | Trojan.Kryptik!8.8 (TFE:3:MccZT5BrisI) |
Yandex | Trojan.GenAsa!Opy9s/e+7g8 |
Ikarus | Trojan.Win32.FakeSysdef |
Fortinet | W32/Krap.AON!tr |
BitDefenderTheta | Gen:NN.ZexaF.34646.cy1@amIJ1jii |
AVG | Win32:FakeAlert-AKX [Trj] |
Panda | Adware/WindowsRecovery |
CrowdStrike | win/malicious_confidence_100% (W) |
What are the symptoms of Nimda trojan?
- Behavioural detection: Executable code extraction – unpacking;
- Sample contains Overlay data;
- Yara rule detections observed from a process memory dump/dropped files/CAPE;
- HTTPS urls from behavior.;
- Reads data out of its own binary image;
- CAPE extracted potentially suspicious content;
- Authenticode signature is invalid;
- Uses Windows utilities for basic functionality;
- Attempts to modify proxy settings;
- Anomalous binary characteristics;
- Uses suspicious command line tools or Windows utilities;
The typical signs and symptom of the Nimda trojan virus is a gradual entrance of different malware – adware, browser hijackers, and so on. Due to the activity of these harmful programs, your personal computer becomes extremely sluggish: malware consumes big amounts of RAM and CPU capabilities.
One more noticeable result of the Nimda trojan virus visibility is unknown programs showed in task manager. In some cases, these processes may attempt to imitate system processes, but you can recognize that they are not legit by taking a look at the source of these processes. Pseudo system applications and Nimda trojan’s processes are always specified as a user’s processes, not as a system’s.
How to remove Nimda trojan virus?
- Download and install Loaris Trojan Remover.
- Open Loaris and perform a “Standard scan“.
- “Move to quarantine” all items.
- Open “Tools” tab – Press “Reset Browser Settings“.
- Approve the reset pressing “Yes” button in the appeared window.
- Restart your computer.
To get rid of Nimda trojan and also ensure that all extra malware, downloaded with the help of this trojan, will be deleted, too, I’d recommend you to use Loaris Trojan Remover.
Nimda removal guide
To detect and delete all viruses on your personal computer using Loaris, it’s better to use Standard or Full scan. Removable scan, as well as Custom, will scan only specified locations, so such checks are not able to provide the full information.
You can observe the detects till the scan process lasts. Nevertheless, to execute any actions against detected malicious programs, you need to wait until the scan is finished, or to stop the scanning process.
To choose the specific action for each detected malicious programs, click the knob in front of the detection name of detected viruses. By default, all viruses will be moved to quarantine.
How to remove Nimda Trojan?
Name: Nimda
Description: Trojan Nimda is a kind of virus that infiltrates into your computer, and after that performs different destructive functions. These features depend upon a type of Nimda trojan: it can act as a downloader for many other malware or as a launcher for another destructive program which is downloaded in addition to the Nimda trojan. During the last two years, trojans are also dispersed via e-mail attachments, and most of situations utilized for phishing or ransomware infiltration.
Operating System: Windows
Application Category: Trojan
User Review
( votes)- What is Trojan Horse: https://en.wikipedia.org/wiki/Trojan_horse_(computing)
- Nimda VirusTotal Report: https://www.virustotal.com/api/v3/files/4b8735c1e636fb043a9e09ea3311643dbfd36742db391892bc9a104510bd84d4