Malware

What is “BrowserModifier.NSIS.Xiazai.R”?

Malware Removal

The BrowserModifier.NSIS.Xiazai.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BrowserModifier.NSIS.Xiazai.R virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine BrowserModifier.NSIS.Xiazai.R?


File Info:

name: BBEB9A0252FAE8BB9DCD.mlw
path: /opt/CAPEv2/storage/binaries/639611341aaf51154b5bb5227b9988976bd05ae3766409cf39064a36d227ce27
crc32: 1903D211
md5: bbeb9a0252fae8bb9dcd375d27812b3d
sha1: 2ca0dc357eedbd0b52857531043d3e6e441f5b90
sha256: 639611341aaf51154b5bb5227b9988976bd05ae3766409cf39064a36d227ce27
sha512: e635cfe7b400ffffc51dfdd19766aa2777b9bfbddb37f1aaadd826de4ca1fb172f1ada97dd677bd12717aa0622aa84e7a200816b46aff8380238fd0b014d2e07
ssdeep: 3072:mbzUckFZWFT+xclcA5dUSmUmONPc3fBVHRO16Hdp1wyR:m/AFZ8+aH5d+UmNfBfm6HjpR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2B3AE26BBD58466D24E99332EA2C3F60070BC0152E0555727D6BFAF7636381E1287BF
sha3_384: d275085aaf97c7714bb8ce3e4201a07a800f4ed288524559009b92f6e4cc9daccf59efe8baa14e87d6185a01225935c2
ep_bytes: 81ec840100005355565733db68018000
timestamp: 2016-06-20 08:42:23

Version Info:

FileDescription: Downloader
FileVersion: 6.0.0.1
LegalCopyright:
OriginalFilename: Downloader
ProductName: Downloader
ProductVersion: 6.0.0.1
Translation: 0x0804 0x03a8

BrowserModifier.NSIS.Xiazai.R also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.94687
ClamAVWin.Trojan.Siggen-6261194-0
FireEyeTrojan.GenericKDZ.94687
CAT-QuickHealBrowserModifier.NSIS.Xiazai.R
ALYacTrojan.GenericKDZ.94687
Cylanceunsafe
ZillyaAdware.Agent.Win32.102399
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005195d71 )
AlibabaTrojan:Win32/Xiazai.96980cb8
K7GWTrojan ( 005195d71 )
CrowdStrikewin/grayware_confidence_100% (W)
CyrenW32/Mikey.U.gen!Eldorado
SymantecPUA.Downloader
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKDZ.94687
AvastOther:Malware-gen [Trj]
TencentMalware.Win32.Gencirc.10bdef88
SophosMal/Generic-S
DrWebTrojan.Siggen7.65186
VIPRETrojan.GenericKDZ.94687
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftTrojan.GenericKDZ.94687 (B)
GDataTrojan.GenericKDZ.94687
JiangminAdWare.Agent.aizv
Antiy-AVLGrayWare[AdWare]/Win32.PackedNsisMod.o
ArcabitTrojan.Generic.D171DF
SUPERAntiSpywarePUP.DownloadAdmin/Variant
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
AhnLab-V3PUP/Win32.Installer.R185010
McAfeePUP-FRS
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware.AI.DDS
YandexPUA.Downloader!LnA66Z1Z2LM
IkarusBHO.Win32.Xiazai
MaxSecureDownloader.NSIS.Hafen.gen
FortinetW32/GenericKDZ.94687!dam
AVGOther:Malware-gen [Trj]
Cybereasonmalicious.57eedb
DeepInstinctMALICIOUS

How to remove BrowserModifier.NSIS.Xiazai.R?

BrowserModifier.NSIS.Xiazai.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment