Malware

NSIS/Injector.ANX removal instruction

Malware Removal

The NSIS/Injector.ANX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/Injector.ANX virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net
crl.sectigo.com

How to determine NSIS/Injector.ANX?


File Info:

name: F8CB20390A8DD4713FB6.mlw
path: /opt/CAPEv2/storage/binaries/4959de8067a62478d5192edb0c7822484ea3f75c643100b4c73b0165eadd8911
crc32: 5159E60C
md5: f8cb20390a8dd4713fb6fc7d1fba553a
sha1: 696508cf33bbeef311b6c9cbe60a152850c4d508
sha256: 4959de8067a62478d5192edb0c7822484ea3f75c643100b4c73b0165eadd8911
sha512: 2230d6550ddfe5118af018ec86aabb4e1c3dc510a3d09b38b4182da82964a34ecb830338db147217a2acdea39075a4fa443326d9dfdadd9806089b38e3a66932
ssdeep: 98304:V+PZ6yLzqoCMMo92wyIlRjKqE3Laq4KrGJkkbA71NNTLI:V+wWzMg92wJG3R0kqb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11816337ADEC9F523C814A6BED411B6F30A760DE9ECE90A4BEE503E093531EF44272645
sha3_384: b65c6e41f08775ea8397922287734fec61b257b0357c2d4ed736203f3c894e2f0c1784a0f91b3fbff6818a4756a447fb
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:57:46

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Security notification icon
FileVersion: 10.0.18362.628 (WinBuild.160101.0800)
InternalName: SecurityHealthSystray
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: SecurityHealthSystray.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.18362.628
Translation: 0x0409 0x04b0

NSIS/Injector.ANX also known as:

LionicTrojan.Win32.Deyma.a!c
ALYacBackdoor.Agent.BitRAT
CylanceUnsafe
ZillyaDownloader.Deyma.Win32.405
SangforTrojan.Win32.Deyma.gen
K7AntiVirusTrojan ( 005899071 )
AlibabaTrojan:Win32/Injector.50008618
K7GWTrojan ( 005899071 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32NSIS/Injector.ANX
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-Downloader.Win32.Deyma.gen
BitDefenderTrojan.GenericKD.47269231
MicroWorld-eScanTrojan.GenericKD.47269231
Ad-AwareTrojan.GenericKD.47269231
EmsisoftMalCert-S.MG (A)
ComodoMalware@#ek6v9o1ry58f
DrWebBackDoor.Rat.388
TrendMicroTrojanSpy.Win32.PARALAXRAT.A
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.47269231
SophosMal/Generic-S
GDataTrojan.GenericKD.47269231
JiangminNetTool.FRP.ak
WebrootW32.Trojan.Gen
AviraTR/Injector.fasxk
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D2D1456F
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Frs.C4734538
McAfeeArtemis!F8CB20390A8D
MAXmalware (ai score=87)
VBA32TrojanDownloader.Deyma
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTrojanSpy.Win32.PARALAXRAT.A
RisingTrojan.Injector/NSIS!1.BFBB (CLASSIC)
AVGNSIS:MalwareX-gen [Trj]
AvastNSIS:MalwareX-gen [Trj]

How to remove NSIS/Injector.ANX?

NSIS/Injector.ANX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment