We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
TrojanDownloader:Win32/Nuwar.A
Detected by Microsoft Defender Antivirus
Aliases: Email-Worm.Win32.Zhelatin.af (Kaspersky) W32/Tibs.gen38 (Norman) Mal/EncPk-E (Sophos) VIPRE.Suspicious (Sunbelt Software) Trojan.Packed.13 (Symantec) TROJ_SMALL.DUR (Trend Micro)
Summary
TrojanDownloader:Win32/Nuwar.A is a Trojan that downloads data from hard-coded remote Web sites. The downloaded information usually includes encrypted hyperlinks to malicious programs. TrojanDownloader:Win32/Nuwar.A connects to the specified URL, then downloads and executes the linked executables.
TrojanDownloader:Win32/Nuwar.A may download and install additional malicious software, thus manual removal is not recommended. To detect and remove this Trojan and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, visit http://www.microsoft.com/athome/security/downloads/default.mspx.