Malware

NSIS/Injector.JV information

Malware Removal

The NSIS/Injector.JV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/Injector.JV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Reads data out of its own binary image
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Anomalous binary characteristics

Related domains:

qkcpahvch.click
yqjvhne.biz
aixqldkdobmvf.org
kwlcevbwuyhkfuopl.xyz
bcqgqubo.click
ftfkgqe.info
ehnpmfircnyyynb.org
bugjkkvo.work
wggsuaxkrvumv.pl
xkiodrqgpn.click

How to determine NSIS/Injector.JV?


File Info:

crc32: 9A87ED84
md5: 56232c51b083fc32b51d6580ac9f378c
name: 56232C51B083FC32B51D6580AC9F378C.mlw
sha1: 2289b0d20fe9a3da48b2ca88882d7cb43a6fec51
sha256: f99f3844949196ce02823d4d185e96a7c7de391f1a1c8f4174c6fffa21766c93
sha512: de2a221c2d7b10956ababb0c271b1d040a8b1d14d1abfe36964884b3954064119b59c74729fbb431e761846dd0d9612f724af86aeed5393d7737099c19c07269
ssdeep: 6144:bB+pgUAHB7fhcrsihtbP6bBfaJsUEm1YUNi:bg4Hpfhc7bP6boJsaYX
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: Copyright (c) Insecure.Com LLC (fyodor@insecure.org)
InternalName: NmapInstaller.exe
FileVersion: 5.36.0.4
CompanyName: Insecure.org
ProductName: Nmap
FileDescription: Nmap installer
LegalTrademark: NMAP
Translation: 0x0409 0x04b0

NSIS/Injector.JV also known as:

K7AntiVirusTrojan ( 0055e4081 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3976
CynetMalicious (score: 99)
CylanceUnsafe
ZillyaTrojan.Locky.Win32.1336
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0055e4081 )
Cybereasonmalicious.20fe9a
SymantecRansom.TeslaCrypt
ESET-NOD32NSIS/Injector.JV
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Encoder.eikegp
TencentWin32.Trojan.Locky.Sttz
SophosMal/Generic-R + Troj/Locky-RK
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_LOCKY.F116JV
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.dc
FireEyeGeneric.mg.56232c51b083fc32
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Locky.A
AegisLabTrojan.Win32.Locky.j!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.Agent.GZNEEO
TACHYONRansom/W32.Locky.212543
AhnLab-V3Trojan/Win32.Locky.C1635872
McAfeeArtemis!56232C51B083
MAXmalware (ai score=100)
MalwarebytesRansom.Cerber
PandaTrj/CI.A
TrendMicro-HouseCallRansom_LOCKY.F116JV
IkarusTrojan.NSIS.Injector
FortinetW32/Injector.IK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove NSIS/Injector.JV?

NSIS/Injector.JV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment