Malware

NSIS/Injector.WD information

Malware Removal

The NSIS/Injector.WD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/Injector.WD virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine NSIS/Injector.WD?


File Info:

crc32: 68359AE1
md5: 01c2c4221937ff36f105ac6b3926008a
name: 01C2C4221937FF36F105AC6B3926008A.mlw
sha1: ad9ecad08b377139cd8ad5369cb575698f6c8ec9
sha256: 15cd51dd6a4aa5d2ec336299259ed5c92f50b3001f87d62597fbaa9ee7d5098c
sha512: 32e80f3e7d720aef6f0906749ab4a8f5400dc1c32f9a4e2fd297a81dcadae30ebdc5e6c12adba75e32942ed1f0130a28ee414f48f9638031cdda1eeb34a27f9c
ssdeep: 12288:Z2yY+WSQP0Wp4xvOKcmKYVI8hKR5QFMjGH8SeawPT/ac/HttL4if1C:Z2yY+4P7pIjc/YVThQcH8SeNTLn1U
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: RVM
FileVersion: 0.6.7
CompanyName: RVM
LegalTrademarks: RVM
Comments: This installation was built with NSIS.
ProductName: SMPlayer
FileDescription: SMPlayer for Windows
Translation: 0x0409 0x04e4

NSIS/Injector.WD also known as:

MicroWorld-eScanTrojan.GenericKD.6022722
FireEyeTrojan.GenericKD.6022722
ALYacTrojan.GenericKD.6022722
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005170701 )
BitDefenderTrojan.GenericKD.6022722
K7GWTrojan ( 005170701 )
Cybereasonmalicious.21937f
SymantecTrojan.Gen
Paloaltogeneric.ml
AlibabaTrojan:Win32/Predator.20dd99ff
NANO-AntivirusTrojan.Win32.Mlw.fgagrr
Ad-AwareTrojan.GenericKD.6022722
EmsisoftTrojan.GenericKD.6022722 (B)
ComodoMalware@#1tzqwzicppqkx
F-SecureHeuristic.HEUR/AGEN.1127501
DrWebTrojan.DownLoader25.35492
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
SophosMal/Generic-S
AviraHEUR/AGEN.1127501
MAXmalware (ai score=99)
MicrosoftTrojan:Win32/Predator.GJ!MTB
ArcabitTrojan.Generic.D5BE642
GDataTrojan.GenericKD.6022722
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Globeimposter.R209326
McAfeeArtemis!01C2C4221937
VBA32Trojan.MSIL.Crypt
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of NSIS/Injector.WD
TencentMsil.Trojan.Crypt.Eyc
IkarusTrojan.NSIS.Agent
FortinetW32/Injector.XG!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Ransom.Shade.HoMASOQA

How to remove NSIS/Injector.WD?

NSIS/Injector.WD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment