Threat Database Worms Worm.Nohad.A

Worm.Nohad.A

By CagedTech in Worms

Threat Scorecard

Popularity Rank: 22,024
Threat Level: 50 % (Medium)
Infected Computers: 1,449
First Seen: April 28, 2019
Last Seen: April 27, 2026
OS(es) Affected: Windows

The detection of Worm.Nohad.A on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the detected threat, its operating characteristics, symptoms of infection, and steps to remove it from your system.

What Is Worm.Nohad.A?

Worm.Nohad.A is a type of malicious software, or malware, that has been identified as a worm. Worms are self-replicating malware that can spread from system to system without the need for human interaction. They often exploit vulnerabilities in software or operating systems to infect new hosts. The name Worm.Nohad.A suggests it is a specific variant of malware, but without further information, its exact nature and capabilities can only be generalized from the characteristics of worms in general.

How Worm.Nohad.A Operates

Like other worms, Worm.Nohad.A is designed to replicate itself and spread to other systems. It may use various methods to propagate, including exploiting vulnerabilities in operating systems, applications, or using social engineering tactics to trick users into executing the malware. Once infected, a system can become a source of further infections, putting other systems at risk. Worms can also be used as a vector for other types of malware, such as Trojans or ransomware, making them a significant security threat.

Symptoms of Infection

Symptoms of a Worm.Nohad.A infection can vary, but common indicators include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You might also notice increased network activity, as the worm attempts to spread to other systems. In some cases, no symptoms may be apparent, making regular system monitoring and antivirus scans crucial for early detection.

  • Unexplained changes in system settings or files
  • Appearance of unfamiliar programs or icons
  • Increased pop-up ads or unexpected browser behavior
  • System crashes or blue screen of death

How to Remove Worm.Nohad.A

  1. Boot your system in Safe Mode with Networking to prevent the worm from loading and to allow for internet access for updates and scans.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure the tool is updated with the latest definitions before scanning.
  3. Uninstall any suspicious programs or applications that were installed around the time of the infection.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes.
  5. After completing the above steps, reboot your system and perform another full scan with your anti-malware tool to ensure all traces of the worm have been removed.

Conclusion

Removing Worm.Nohad.A from your system requires careful and thorough steps to ensure all components of the malware are eliminated. It's crucial to stay vigilant and maintain good security practices, including keeping your operating system and software up to date, using strong antivirus protection, and being cautious with emails and downloads. Regular system backups can also help mitigate the impact of future infections. By following the removal steps outlined and maintaining a secure computing environment, you can help protect your system and data from Worm.Nohad.A and other malware threats.

Analysis Report

General information

Family Name: Worm.Nohad.A
Signature status: No Signature

Known Samples

MD5: f20ae01a74f763aadb0f8255a82157df
SHA1: d8d1dd355a98c4c444b5094663f70caf624c5a30
SHA256: 2C37B93FDE7CEDFDC6D328B43C532E9FD0C4B173A1BF7D4C6E0EAA54792790CE
File Size: 4.09 MB, 4091515 bytes
MD5: 51d1f06f8f4750cbcba9279ddf9ad6b6
SHA1: 7cc3b10b165d905bfc5859d951df2c771ec97f9b
SHA256: D6F2A5DCFF6B1375FA75D550C808DAA3F5A122D3EF9887361A1652479776E2B3
File Size: 3.81 MB, 3814020 bytes
MD5: c1c09298eebb9885553aba3087fce86f
SHA1: e05816c52cb6956b763cdada7aec70731e407663
SHA256: 64DF5A36F4D9E147AFA85E697642488292DC2BC49C832821C3A01DC6A0A7F56C
File Size: 4.09 MB, 4091591 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments www.facebook.com/llaneroinformatico
Company Name Perú
File Description Explorador de Windows
File Version
  • 1.00
  • 1.0.0.0
Internal Name
  • llanero solitario
  • TJprojMain
Legal Copyright llanero solitario
Legal Trademarks llanero solitario
Original Filename
  • llanero solitario
  • TJprojMain.exe
Product Name
  • llanero solitario
  • Project1
Product Version
  • 1.00
  • 1.0.0.0

File Traits

  • 2+ executable sections
  • VirtualQueryEx
  • x86

Block Information

Similar Families

  • InstallMonstr.B

Files Modified

File Attributes
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\nottepad.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\nottepad.exe Synchronize,Write Attributes
c:\users\user\documen Synchronize,Write Attributes
c:\users\user\documen\nod42.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\documen\nod42.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\advanced::hidden  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecute
User Data Access
  • GetUserObjectInformation

Shell Command Execution

open C:\Users\Gcdogrhb\Documen\nod42.exe
open c:\users\user\downloads\7cc3b10b165d905bfc5859d951df2c771ec97f9b_0003814020

Related Posts

Trending

Most Viewed

Loading...