Malware

What is “NSIS/Injector.ABA”?

Malware Removal

The NSIS/Injector.ABA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/Injector.ABA virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine NSIS/Injector.ABA?


File Info:

crc32: 7302A0C4
md5: b9091ef41de734fdbd7c7df7b2a5ea20
name: B9091EF41DE734FDBD7C7DF7B2A5EA20.mlw
sha1: 4d313c6379933dfcfc79cab04a7c83899862b0d7
sha256: 3ad3e9feca98bd1c94415f0319340c3c9416541f4592f7373aeeab289a03c7ac
sha512: f3aa29e6d4f77d36d1d6a0da1d88e69e69af9bed81a63b85869b1d2582a3e5ff121b9ac8a8b33e2d3f329569fcc3c5370b23da3bdca5636db91c9b6a98813733
ssdeep: 6144:E1onIw+yeYJGW5jt6IAqQXkZ52XZFF64v9VXbBkl/TEJf5:soIwZ5HQ083FPlVX6p+f5
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: Copyright ? 2018 FoldingBrowser
FileVersion: 17
CompanyName: FoldingBrowser
Comments: FoldingBrowser v17 Installer
ProductName: FoldingBrowser v17
FileDescription: FoldingBrowser v17 Installer
Translation: 0x0409 0x0000

NSIS/Injector.ABA also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052ed641 )
LionicTrojan.Win32.Generic.m!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.2255
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.30904287
CylanceUnsafe
SangforBackdoor.Win32.Agent.gen
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:Win32/Injector.8440bcc4
K7GWTrojan ( 0052ed641 )
Cybereasonmalicious.41de73
SymantecRansom.Rapid
ESET-NOD32NSIS/Injector.ABA
APEXMalicious
AvastNSIS:CoinMiner-C [Trj]
ClamAVWin.Dropper.Nemesis-6646739-0
KasperskyHEUR:Backdoor.Win32.Agent.gen
BitDefenderTrojan.GenericKD.30904287
NANO-AntivirusTrojan.Win32.Steam.fgahap
MicroWorld-eScanTrojan.GenericKD.30904287
TencentWin32.Backdoor.Agent.Pdvt
Ad-AwareTrojan.GenericKD.30904287
SophosMal/Generic-S
ComodoMalware@#67un7mtu9tv8
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPLOKI.SMAL3
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.fc
FireEyeGeneric.mg.b9091ef41de734fd
EmsisoftTrojan.GenericKD.30904287 (B)
AviraHEUR/AGEN.1127498
MicrosoftTrojan:Win32/Occamy.B
GridinsoftTrojan.Win32.Injector.sd!s5
ArcabitTrojan.Generic.D1D78FDF
SUPERAntiSpywareTrojan.Agent/Gen-Injector
GDataTrojan.GenericKD.30904287
McAfeeArtemis!B9091EF41DE7
MAXmalware (ai score=98)
VBA32Backdoor.Agent
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_HPLOKI.SMAL3
FortinetW32/Injector.XG!tr
AVGNSIS:CoinMiner-C [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Miner.Coinminer.HyoDEpsA

How to remove NSIS/Injector.ABA?

NSIS/Injector.ABA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment