Trojan

NSIS/TrojanDropper.Agent.BT removal tips

Malware Removal

The NSIS/TrojanDropper.Agent.BT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/TrojanDropper.Agent.BT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
fget-career.com
bing.com
yahoo.com
www.qq5.com

How to determine NSIS/TrojanDropper.Agent.BT?


File Info:

crc32: 4C85DB3E
md5: f14400627d9a38e81fb94001f6b69b3b
name: shishangzuikengdiedieluosifangkuai.exe
sha1: ab1060d205a630e4e9a90161a66e0e19d1f70309
sha256: f520501650dfd4a7153beb585b91802bd80358ed830d821e3677550312460a66
sha512: a50560664a0f62f455736f762dc29ccf074aed701ba4a2a56bdff5045b563a480d95ca4ee69b3451073c4bf19d7cc13c4616fdaa3e4d4c0a9495c7e059537b45
ssdeep: 196608:Vgiyw5wzOXtL6UGZ2XnuQv938jScwGflEHd:+5awkTu+8jtlEHd
type: PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive

Version Info:

LegalCopyright: (C)
ProductName:
FileVersion:
FileDescription: Producer shd
Translation: 0x0804 0x04e4

NSIS/TrojanDropper.Agent.BT also known as:

MicroWorld-eScanTrojan.GenericKD.31747835
FireEyeGeneric.mg.f14400627d9a38e8
CAT-QuickHealW32.Ramnit.A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabVirus.Win32.Nimnul.n!c
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderTrojan.GenericKD.31747835
K7GWTrojan ( 0050b64b1 )
K7AntiVirusTrojan ( 0050b64b1 )
Invinceaheuristic
BaiduMulti.Threats.InArchive
F-ProtW32/Ramnit.B!Generic
SymantecW32.Ramnit!inf
APEXMalicious
AvastWin32:RmnDrp
ClamAVWin.Trojan.Ramnit-1847
GDataTrojan.GenericKD.31747835
KasperskyVirus.Win32.Nimnul.a
AlibabaVirus:Win32/Nimnul.b8264b25
NANO-AntivirusVirus.Win32.Ramnit.eslalb
TencentMalware.Win32.Gencirc.10b3ee0c
Ad-AwareTrojan.GenericKD.31747835
EmsisoftAdware.Dropper (A)
ComodoMalware@#29ishag43kmmv
F-SecureMalware.W32/Ramnit.CD
DrWebAdware.Searcher.1222
ZillyaTrojan.Zbot.Win32.188716
TrendMicroPE_RAMNIT.H
McAfee-GW-EditionBehavesLike.Win32.Virus.vc
Trapminemalicious.high.ml.score
SophosW32/Patched-I
IkarusVirus.Ramnit
CyrenW32/Ramnit.B!Generic
JiangminWin32/PatchFile.et
MaxSecureVirus.Nimnul.A
AviraW32/Ramnit.CD
MAXmalware (ai score=100)
Antiy-AVLGrayWare/Win32.StartPage.gen
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1E46EFB
ZoneAlarmVirus.Win32.Nimnul.a
MicrosoftVirus:Win32/Ramnit.A
BitDefenderThetaAI:FileInfector.EAEEA7850C
ALYacTrojan.GenericKD.31747835
VBA32Adware.Searcher
MalwarebytesTrojan.ChinAd
PandaGeneric Suspicious
ZonerTrojan.Win32.Ramnit.23698
ESET-NOD32a variant of NSIS/TrojanDropper.Agent.BT
TrendMicro-HouseCallPE_RAMNIT.H
RisingVirus.Ramnit!1.9AA5 (CLASSIC)
SentinelOneDFI – Malicious PE
FortinetW32/Agent.BT!tr
WebrootW32.Malware.Heur
AVGWin32:RmnDrp
Cybereasonmalicious.27d9a3
Paloaltogeneric.ml
Qihoo-360Win32/Virus.IM.0e1

How to remove NSIS/TrojanDropper.Agent.BT?

NSIS/TrojanDropper.Agent.BT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment