Trojan

NSIS/TrojanDropper.Agent.DZ removal instruction

Malware Removal

The NSIS/TrojanDropper.Agent.DZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/TrojanDropper.Agent.DZ virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine NSIS/TrojanDropper.Agent.DZ?


File Info:

name: EBD73A11B2FB339C11C0.mlw
path: /opt/CAPEv2/storage/binaries/18e7999e8f6a59a0165806674a235e7e7789b18282f08c863280cccf19cdbc76
crc32: D5CB70D7
md5: ebd73a11b2fb339c11c08f463d6f268e
sha1: b0cc24843082860ab36b83acd7ba8fcaeda58712
sha256: 18e7999e8f6a59a0165806674a235e7e7789b18282f08c863280cccf19cdbc76
sha512: 009851c05a5bee3b1767a2803a87509e87b78c2821611768dec2efc9ad1eec2c1a090405939d1cb70396bb04fbfc63732289c162241794d58524f096ddb8d5b2
ssdeep: 98304:KyS28dONqGywRJ31iC4xRVz1QnmAwdlv26sy/DshvoPJdEf+GmYSjshiUC:lIdxGy+bkV1fDO6s4DshvmJdFGmh8C
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T141363307BE0BBCB3C9302172D0B65B561A384F269DC893C67BC97F64ABB06D0B665714
sha3_384: f550fb74716ff4b4bb3d602fdb05bebefc20a86044c195ffbe07983439199e9f095929c8585e22a048b3c355e5b90e33
ep_bytes: 5589e557565381ec0c030000c7042401
timestamp: 2019-01-07 09:09:57

Version Info:

0: [No Data]

NSIS/TrojanDropper.Agent.DZ also known as:

LionicTrojan.NSIS.Agent.b!c
MicroWorld-eScanGen:Variant.Bulz.403119
ClamAVWin.Ransomware.Protected-9838686-0
FireEyeGeneric.mg.ebd73a11b2fb339c
ALYacGen:Variant.Bulz.403119
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0002fcd31 )
AlibabaTrojanDropper:Win32/DropperX.dde7441f
K7GWTrojan ( 0002fcd31 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Bulz.AH.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32NSIS/TrojanDropper.Agent.DZ
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Dropper.NSIS.Agent.gen
BitDefenderGen:Variant.Bulz.403119
AvastNSIS:DropperX-gen [Drp]
TencentWin32.Trojan.FalseSign.Ojgl
Ad-AwareGen:Variant.Bulz.403119
SophosGeneric ML PUA (PUA)
DrWebTrojan.SpyBot.1107
VIPREGen:Variant.Bulz.403119
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Bulz.403119 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Bulz.403119
JiangminTrojanSpy.Windigo.ub
AviraHEUR/AGEN.1231544
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.547
ZoneAlarmHEUR:Trojan-Dropper.NSIS.Agent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3PUP/Win.Generic.R374008
Acronissuspicious
McAfeeArtemis!EBD73A11B2FB
VBA32suspected of Trojan.Downloader.gen
MalwarebytesTrojan.Dropper.NSIS
RisingDropper.Agent/NSIS!1.D57D (CLASSIC)
FortinetNSIS/Agent.DZ!tr
AVGNSIS:DropperX-gen [Drp]
Cybereasonmalicious.1b2fb3
PandaTrj/CI.A

How to remove NSIS/TrojanDropper.Agent.DZ?

NSIS/TrojanDropper.Agent.DZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment