Trojan

NSIS/TrojanDownloader.Agent.NYT removal instruction

Malware Removal

The NSIS/TrojanDownloader.Agent.NYT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/TrojanDownloader.Agent.NYT virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine NSIS/TrojanDownloader.Agent.NYT?


File Info:

name: C5E990DACA7748CD54A4.mlw
path: /opt/CAPEv2/storage/binaries/bb8c0a19eb45f0cbca0a557d76da70809ad41328f7dff7a615f5ea3a9b711117
crc32: 9504F2F8
md5: c5e990daca7748cd54a4f973adf351cc
sha1: a5a46c324eede7052fd640fa4c72b408a150b9fd
sha256: bb8c0a19eb45f0cbca0a557d76da70809ad41328f7dff7a615f5ea3a9b711117
sha512: d11dec27ba2cc69aa5323ac70f89f2fe620fd3f9219e9e51d8899c73857196e6685e5c5ef99d8f60563fcefa926284102f4a0744f3ca2dfc05be060b4b2813db
ssdeep: 3072:18UWylM4JDVPYuFNDuvz0KDm5r8Wl7mGCKZQDm5rj:BlHXJWffO9Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142D3E0327380D5A7CAE2C63010F662779F35A874F6519E0313E45A2F7DA2282DB1E383
sha3_384: d19421e50f6272e86248fcb020591cbb5caf0b0559c013359e833bd9ef8b9494e124407cf33dfa4ea45cf879cadd57c7
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2019-12-16 00:50:59

Version Info:

0: [No Data]

NSIS/TrojanDownloader.Agent.NYT also known as:

LionicAdware.Win32.Agent.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.GenericKD.47475770
FireEyeAdware.GenericKD.47475770
ALYacAdware.GenericKD.47475770
AlibabaAdWare:Win32/Generic.b31b0d98
K7GWTrojan-Downloader ( 0056b7271 )
K7AntiVirusTrojan-Downloader ( 0056b7271 )
CyrenW32/Agent.BWI.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32NSIS/TrojanDownloader.Agent.NYT
APEXMalicious
ClamAVWin.Malware.Generic-9829478-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Agent.gen
BitDefenderAdware.GenericKD.47475770
NANO-AntivirusTrojan.Nsis.Agent.hvvmtn
AvastWin32:Adware-gen [Adw]
TencentNsis.Trojan-downloader.Agent.Taov
Ad-AwareAdware.GenericKD.47475770
SophosMal/Generic-R + Mal/Agent-AVH
DrWebTrojan.Siggen9.59153
TrendMicroTROJ_GEN.R002C0RKN21
McAfee-GW-EditionArtemis!PUP
EmsisoftAdware.GenericKD.47475770 (B)
GDataAdware.GenericKD.47475770
AviraHEUR/AGEN.1137638
ArcabitAdware.Generic.D2D46C3A
ViRobotTrojan.Win32.Z.Agent.141968
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Adware/Win32.Agent.R348146
McAfeeArtemis!C5E990DACA77
MAXmalware (ai score=69)
VBA32Adware.Agent
MalwarebytesAdware.BundleInstaller
TrendMicro-HouseCallTROJ_GEN.R002C0RKN21
FortinetNSIS/Agent.FDC8!tr
AVGWin32:Adware-gen [Adw]

How to remove NSIS/TrojanDownloader.Agent.NYT?

NSIS/TrojanDownloader.Agent.NYT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment