Malware

NSIS/Injector.GF (file analysis)

Malware Removal

The NSIS/Injector.GF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/Injector.GF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Cerber ransomware
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine NSIS/Injector.GF?


File Info:

crc32: A7254F97
md5: 8a27e742231d30c601b9958b9e2812ec
name: 8A27E742231D30C601B9958B9E2812EC.mlw
sha1: 7eeb41af37c1a31b48fe26e11ae30f9a52ddb0ce
sha256: b4e92ffafaf70743b33515520e2d9ce79ba4ff0780172a82643db999e3cfed89
sha512: f7cdc1cc839cdb6f75c18619d7aa5c56e96d67d7f700cf4c2e2791dc6514e76428c66962d499a0d0a466a857bcd218a3a13764e3847cccb85e48336e377d30c1
ssdeep: 6144:sW+7+eMRXltznkTEFenaN8vg3jvT/Y3UV4WUX6vl4YkR68bnZ/FI:sR6XbnkThaz3jvLD92HFI
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

NSIS/Injector.GF also known as:

BkavW32.AIDetect.malware1
FireEyeGeneric.mg.8a27e742231d30c6
CAT-QuickHealRansom.Locky.A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Generic.8
K7AntiVirusTrojan ( 004fa5151 )
K7GWTrojan ( 004fa5151 )
Cybereasonmalicious.f37c1a
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Spyware-gen [Spy]
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Injector.1d44ef7a
NANO-AntivirusTrojan.Win32.ObfusRansom.eshqcc
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Inject.Auto
TACHYONRansom/W32.Cerber.288935
SophosMal/Generic-R + Mal/Miuref-L
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Encoder.4691
TrendMicroRansom_CERBERENC.SMNS5
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
IkarusTrojan.NSIS.Injector
AviraTR/Dropper.Gen
MicrosoftRansom:Win32/Cerber.A
SUPERAntiSpywareRansom.Cerber/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cerber.R188788
McAfeeArtemis!8A27E742231D
MAXmalware (ai score=100)
MalwarebytesRansom.Cerber
PandaTrj/CI.A
ESET-NOD32NSIS/Injector.GF
TrendMicro-HouseCallRansom_CERBERENC.SMNS5
YandexTrojan.Agent!Wh7UlrVs6oA
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.GD!tr
AVGWin32:Spyware-gen [Spy]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Ransom.9c1

How to remove NSIS/Injector.GF?

NSIS/Injector.GF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment