Malware

What is “NSIS/Injector.BUR”?

Malware Removal

The NSIS/Injector.BUR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/Injector.BUR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A scripting utility was executed

How to determine NSIS/Injector.BUR?


File Info:

name: BEC78DF47FF8CF0B1961.mlw
path: /opt/CAPEv2/storage/binaries/fb4acd018acf7a2682ea82e941f8167c2008bbdb7fec77ef8fc91d786835c309
crc32: DE08BF10
md5: bec78df47ff8cf0b1961430b92790ae0
sha1: 25500dd32e965451340cf48d1c010d3840cfebcc
sha256: fb4acd018acf7a2682ea82e941f8167c2008bbdb7fec77ef8fc91d786835c309
sha512: 7e37393ec7c0ad3bbd9e9c649556303176e77cfd7e1c9c3f7e03bcc4ae4b5fe30266402e6d5d60695bb40c6609934944d1cf99448089a12814a131d2ce700e18
ssdeep: 6144:Tps/ya+u+kM3zB99Go0YAP9vVbOOt2AeNDyQ2cQn7bk6bhs/+EeP:Fa+uGjv0YUVbLHcGFbhs/YP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1105412433BB4C5B3F5A4CBB1F9BB6F1B2FB9507C8658134B7B448A5438924B58B0E909
sha3_384: a64a6e321dc504ec4a4cf77f2cb593f71b3b1dd2f55166043757ef8083e971ec497617d53918fbc20f40805e24a3155d
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-12-11 21:50:52

Version Info:

Comments: Superheterodyne Ubedragelige Biotin
CompanyName: Blundens dommersders
FileVersion: 1.4.0.0
LegalTrademarks: Brumbasserne
ProductName: spndeskivernes Skyttekders
Translation: 0x0409 0x04e4

NSIS/Injector.BUR also known as:

LionicTrojan.Win32.Alien.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.65601489
FireEyeTrojan.GenericKD.65601489
CAT-QuickHealTrojan.Guloader
SkyhighRDN/Leonem
McAfeeRDN/Leonem
MalwarebytesTrojan.Dropper
ZillyaTrojan.Alien.Win32.2717
SangforTrojan.Win32.Alien.Vrly
K7AntiVirusTrojan ( 0059f3f61 )
AlibabaTrojan:Win32/Alien.5491e4e9
K7GWTrojan ( 0059f3f61 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Genus.OBP
SymantecTrojan Horse
ESET-NOD32NSIS/Injector.BUR
APEXMalicious
KasperskyHEUR:Trojan.Win32.Alien.gen
BitDefenderTrojan.GenericKD.65601489
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.65601489 (B)
F-SecureHeuristic.HEUR/AGEN.1368750
VIPRETrojan.GenericKD.65601489
TrendMicroTROJ_FRS.0NA103BM23
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
WebrootW32.Malware.Gen
GoogleDetected
AviraHEUR/AGEN.1368750
VaristW32/Trojan.DBRC-7094
Antiy-AVLTrojan/NSIS.Injector
Kingsoftwin32.troj.undef.a
XcitiumMalware@#3lkqkpjj2ojb2
ArcabitTrojan.Generic.D3E8FFD1
ViRobotTrojan.Win.Z.Agent.297032
ZoneAlarmHEUR:Trojan.Win32.Alien.gen
GDataTrojan.GenericKD.65601489
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.GuLoader.C5385348
VBA32Trojan.GuLoader
ALYacTrojan.Agent.GuLoader
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_FRS.0NA103BM23
TencentWin32.Trojan.FalseSign.Yfow
YandexTrojan.Igent.bZEzEW.3
MaxSecureTrojan.W32.Alien.gen
FortinetW32/BUR!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove NSIS/Injector.BUR?

NSIS/Injector.BUR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment