Malware

Should I remove “NSIS/Injector.AIU”?

Malware Removal

The NSIS/Injector.AIU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/Injector.AIU virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine NSIS/Injector.AIU?


File Info:

crc32: 9B319B5E
md5: 4ae812bebf1c3aadd87e6b813cf8fb04
name: upload_file
sha1: 791b293fdbc59b55939cc17d7b61a86785b17ac6
sha256: 0259709a424c0ce720adad9f86158bbb8d5b60c155db6a83f0797fca6feafbba
sha512: f48e924dbd711219a5033758d9be6fa4b3bb671088bdee4c2d856d02578a31ea762c74dffd0a86cad827c2c4ac2939caa67e780340bd264b7a6df7dd85751b1d
ssdeep: 3072:Lf1BDZ0kVB67Duw9AMcMUdJKmDbjUpgp7iPxvqKt0VWUJEUnjI+XkeKNud2W46vs:L9X0GrLIpW0vq7AUrI+XEY2IFKp9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyleft 1998-2016 by Don HO
InternalName: npp.exe
FileVersion: 7.86
CompanyName: Don HO don.h@free.fr
ProductName: Notepad++
ProductVersion: 7.86
FileDescription: Notepad++ : a free (GNU) source code editor
OriginalFilename: Notepad++.exe
Translation: 0x0409 0x04b0

NSIS/Injector.AIU also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34592716
FireEyeGeneric.mg.4ae812bebf1c3aad
ALYacTrojan.Agent.ZLoader
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.34592716
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fdbc59
TrendMicroTrojanSpy.Win32.TRICKBOT.THIBFBO
CyrenW32/Trojan.GWID-1374
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Trickbot.e1905dfd
ViRobotTrojan.Win32.Z.Trickbot.327546
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareTrojan.GenericKD.34592716
SophosMal/Generic-S
F-SecureTrojan.TR/AD.ShellcodeCrypter.skjhv
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Emotet.fh
EmsisoftTrojan.GenericKD.34592716 (B)
IkarusTrojan.NSIS.Agent
JiangminTrojan.Cometer.bbl
WebrootW32.Trojan.Gen
AviraTR/AD.ShellcodeCrypter.skjhv
MAXmalware (ai score=81)
Antiy-AVLTrojan/MSIL.Vasal
MicrosoftTrojan:Win32/Trickbot.GN
ArcabitTrojan.Generic.D20FD7CC
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.ZLoader.18220V
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Amabot.R352381
McAfeeRDN/Generic.dx
VBA32TrojanSpy.Teamspy
PandaTrj/CI.A
ESET-NOD32NSIS/Injector.AIU
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.THIBFBO
RisingTrojan.Injector/NSIS!1.BFBB (CLASSIC)
FortinetW32/Generic.THIBFBO!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Generic/HEUR/QVM42.3.2ADF.Malware.Gen

How to remove NSIS/Injector.AIU?

NSIS/Injector.AIU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment