We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Nuwar.JL
Detected by Microsoft Defender Antivirus
Aliases: W32/Nuwar@MM!rar (McAfee) Mal/DorfRar-A (Sophos) WORM_NUWAR.RAR (Trend Micro)
Summary
Worm:Win32/Nuwar.JL is specific detection for password protected RAR archives containing the Win32/Nuwar worm. The RAR archive is included as an attachment to certain variants of Win32/Nuwar composed e-mail. Included in the RAR archive is a password protected copy of the worm and a GIF image file containing the password, which is displayed as inline html in the e-mail message.
For more information on this threat, see the write-up for Worm:Win32/Nuwar.gen.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as Microsoft Security Essentials, or the Microsoft Safety Scanner. For more information about using antivirus software, see http://www.microsoft.com/security/antivirus/av.aspx.