Malware

NSIS/Injector.AAG removal tips

Malware Removal

The NSIS/Injector.AAG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/Injector.AAG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Spanish
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipv4bot.whatismyipaddress.com

How to determine NSIS/Injector.AAG?


File Info:

crc32: B3FF9158
md5: 2e569aa8ca023d5a64b5a96de384e708
name: 2E569AA8CA023D5A64B5A96DE384E708.mlw
sha1: a00bd87c302f9f926f9393b90df7ff830f8a8f3e
sha256: 742c84df8f7276b744b47325190618ff1c2a433e485baf31d9fbb6e1dd1f7892
sha512: b1f5d00d746c94b323be113b66e32f8742b16b25ba56501d0612ebbe32d31268177040ad0c3dc6ca11c698b6d29239c343aa9c16c14195b321c5447ac0ead2b5
ssdeep: 6144:tppgKU8kTVuGzuOzrXUvVY4wH3qrVlF+XUZYuQ:Bu8kxuYwd66pa9uQ
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright:
FileVersion: 0.7.0
CompanyName: Deployd, LLC
ProductName: Deployd
ProductVersion: 0.7.0
FileDescription:
CompanyWebsite: http://www.deployd.com
Translation: 0x040a 0x04e4

NSIS/Injector.AAG also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052cbdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.30611831
CylanceUnsafe
SangforRansom.Win32.GrandCrab.A
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/GrandCrab.b9465d1a
K7GWTrojan ( 0052cbdf1 )
Cybereasonmalicious.8ca023
CyrenW32/Ransom.LP.gen!Eldorado
ESET-NOD32NSIS/Injector.AAG
AvastNSIS:CoinMiner-C [Trj]
ClamAVWin.Dropper.Nemesis-6646739-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.30611831
MicroWorld-eScanTrojan.GenericKD.30611831
TencentWin32.Trojan.Agent.Htco
Ad-AwareTrojan.GenericKD.30611831
ComodoMalware@#3gf7bceo30ebt
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_GrandCrab.R002C0DD621
FireEyeTrojan.GenericKD.30611831
EmsisoftTrojan.Injector (A)
AviraHEUR/AGEN.1127485
MicrosoftRansom:Win32/GrandCrab.A
GDataTrojan.GenericKD.30611831
AhnLab-V3Trojan/Win32.Gandcrab.R224204
McAfeeArtemis!2E569AA8CA02
MAXmalware (ai score=97)
MalwarebytesRansom.GandCrab
PandaTrj/CI.A
TrendMicro-HouseCallRansom_GrandCrab.R002C0DD621
MaxSecureTrojan.Malware.7388093.susgen
FortinetW32/Injector.XG!tr
AVGNSIS:CoinMiner-C [Trj]
Paloaltogeneric.ml

How to remove NSIS/Injector.AAG?

NSIS/Injector.AAG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment