Malware

Should I remove “NSIS/Injector.VS”?

Malware Removal

The NSIS/Injector.VS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/Injector.VS virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine NSIS/Injector.VS?


File Info:

name: 81B4114D9E738EA4F699.mlw
path: /opt/CAPEv2/storage/binaries/ae4738e6cccdc14f07bd11bf591f297b62febb36804dbd70dbc47e7f51d90f8e
crc32: E6BC0738
md5: 81b4114d9e738ea4f6996522c86b99bb
sha1: d534d935f3dfe833bd11ba8222630b6200f6513b
sha256: ae4738e6cccdc14f07bd11bf591f297b62febb36804dbd70dbc47e7f51d90f8e
sha512: 3ed78fa8b9a828a2b272979fb02f07e073c99887e522a5791f6a90e9dea80ceb29dba8cad11c1a3e48c14d7da123ca26eafc56d8f9a3c236f17c18959e577ccc
ssdeep: 3072:mM1BjoYNXoKDIJBXJPWWZ9EHsGqGkh9ld4Uhq2tP+j13qinLRT:mMMYNXqBBNZAsG2llf+joinR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T103D301623BDA80BBF51347721B7747A8D2BA9300553294CB2B19AFBD6C35683920F5C3
sha3_384: 279355fe6fe3bdbf61b1a18ebe144de5eeba5859aaa0420ddd7021b4a0d1b1edd409a2d2079d2da47edc92c91f485cea
ep_bytes: 81ec8401000053555633db57895c2418
timestamp: 2014-10-07 04:40:10

Version Info:

0: [No Data]

NSIS/Injector.VS also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.81b4114d9e738ea4
McAfeeArtemis!81B4114D9E73
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 00517a8b1 )
AlibabaTrojan:Win32/Injector.fb6c8c79
K7GWTrojan ( 00517a8b1 )
Cybereasonmalicious.5f3dfe
CyrenW32/Trojan.YMGI-4260
SymantecTrojan.Gen.MBT
ESET-NOD32NSIS/Injector.VS
TrendMicro-HouseCallTROJ_GEN.R002C0RB622
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Cerber-9773143-0
KasperskyHEUR:Trojan.Win32.Generic
SUPERAntiSpywareRansom.CryptoLocker/Variant
TencentWin32.Trojan.Generic.Eadg
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0RB622
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
SophosMal/Generic-R + Mal/Cerber-Z
Paloaltogeneric.ml
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Ymacco.AAAE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Zerber.R283225
VBA32Trojan.Wacatac
MalwarebytesMalware.AI.2716138777
APEXMalicious
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetNSIS/Injector.VS!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove NSIS/Injector.VS?

NSIS/Injector.VS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment