Malware

About “NSIS/Injector.ATI” infection

Malware Removal

The NSIS/Injector.ATI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/Injector.ATI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine NSIS/Injector.ATI?


File Info:

name: 8F18BB71F42A1EB3FDB1.mlw
path: /opt/CAPEv2/storage/binaries/3d755b17b2490c3cd1fcd1b4393aeeac6931e573b6bbd1e59a6315e3bad1a809
crc32: E7880C2F
md5: 8f18bb71f42a1eb3fdb1de3ee5f6d06b
sha1: 3b29ae93d818d8cddec82deb0e95f9ec0d9a0732
sha256: 3d755b17b2490c3cd1fcd1b4393aeeac6931e573b6bbd1e59a6315e3bad1a809
sha512: 7115cbd27f8c8db08efb745db895cfc616fb13e767e6503c617e7a99ac4c42304764e86a623601843368ae5b5a6768723e0865b94a9d826751d192deaf7d3628
ssdeep: 12288:KY0Uum5Vg9diyrsRjJLPew51vLQIWkS9o:KY07mkiywRjxPeM1jzWkGo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB9423E16F90E6DFE993983619BB8F134BF8B91655ED250627D15F093C222C2A24F313
sha3_384: 29077aaa0a6371c5f1fb76dd092e7e7d1cc3d2d46559848cf612cd627e01cabef30569bb323a80c8ff72cd60d2cd5b99
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:56:47

Version Info:

Comments: Anheuser-Busch Companies, Inc.
CompanyName: Benchmark Electronics, Inc.
FileDescription: Ecolab Inc.
FileVersion: 15.27.27
LegalCopyright: Marriott International Inc.
LegalTrademarks: Copyright © 1998-2005 Mark Russinovich and Bryce Cogswell
ProductName: Xerox
Translation: 0x0409 0x04b0

NSIS/Injector.ATI also known as:

LionicTrojan.Win32.Shelsy.4!c
MicroWorld-eScanTrojan.GenericKD.39618701
FireEyeTrojan.GenericKD.39618701
ALYacTrojan.GenericKD.39618701
CylanceUnsafe
SangforTrojan.Win32.Shelsy.gen
K7AntiVirusTrojan ( 005922831 )
AlibabaTrojan:Win32/Shelsy.91890aaf
K7GWTrojan ( 005922831 )
ArcabitTrojan.Generic.D25C888D
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32NSIS/Injector.ATI
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Shelsy.gen
BitDefenderTrojan.GenericKD.39618701
AvastNSIS:TrojanX-gen [Trj]
TencentWin32.Trojan.Falsesign.Ebqu
Ad-AwareTrojan.GenericKD.39618701
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionRDN/Sabsik
EmsisoftTrojan.GenericKD.39618701 (B)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Woreflint.A!cl
ViRobotTrojan.Win32.Z.Agent.425232
GDataTrojan.GenericKD.39618701
McAfeeRDN/Sabsik
MAXmalware (ai score=84)
MalwarebytesTrojan.GuLoader
TrendMicro-HouseCallTROJ_GEN.R049C0PE922
IkarusTrojan.NSIS.Agent
MaxSecureTrojan.Malware.121218.susgen
AVGNSIS:TrojanX-gen [Trj]
CrowdStrikewin/grayware_confidence_60% (D)

How to remove NSIS/Injector.ATI?

NSIS/Injector.ATI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment