Adware PUA

NSIS:Adware-MT [PUP] malicious file

Malware Removal

The NSIS:Adware-MT [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Adware-MT [PUP] virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine NSIS:Adware-MT [PUP]?


File Info:

name: 4B6DE6F017697EAFBE83.mlw
path: /opt/CAPEv2/storage/binaries/4e5c4731ad36c46f810b2d7c7d9b929927997f4c8a78278124a38ee3aa5cec2b
crc32: 35313DF5
md5: 4b6de6f017697eafbe8346c9d2354230
sha1: 704ccf52c518c725cdbfa51f3cd6b6e6caf1e889
sha256: 4e5c4731ad36c46f810b2d7c7d9b929927997f4c8a78278124a38ee3aa5cec2b
sha512: 5509e5e0ec21f7f85611d2034bb7a315d556afac152cd7fa77fc956a386a427ad65b9b31d0fce63177c3a3237c39bf22586d69c3c3049433fa56d03d18ed1372
ssdeep: 6144:Me34EoB0Jojo59Fpk0KkB8/BTP827dk4ggqNkL9ECA6dkj/mE3nzLuMte74CqOd:FoBEaGDk0KkcBTP8SxHEC9EC9wDXzLDw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19B74121357C09B73E1E446B648722EE2F373ADD502926DAB575D2F3732249A3492D2C3
sha3_384: 881de7702e70be909590762c5dc4ea89fac486fb523cd3b4e347cf8a0edffe7c595b033f6c828850db3545674696d118
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

Comments: http://自动版.nsi
CompanyName: MeinV
FileDescription: Installer Application
FileVersion: 1.0.1.4
LegalCopyright: 100.nsi_nsis-2.46_238_274552
ProductName: 100.nsi_nsis-2.46_238_274552
ProductVersion: 1.0.1.4
Translation: 0x0000 0x03a8

NSIS:Adware-MT [PUP] also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.DownLoader12.11907
MicroWorld-eScanTrojan.Downloader.Hicrazyk.A
FireEyeTrojan.Downloader.Hicrazyk.A
CAT-QuickHealTrjnDwnldr.NSIS.Hicrazyk.A
McAfeeArtemis!4B6DE6F01769
CylanceUnsafe
SangforPUP.Win32.Agent.MT
AlibabaTrojanDownloader:Win32/Hicrazyk.343e0d6f
Cybereasonmalicious.017697
VirITTrojan.Win32.Generic.HJI
CyrenW32/A-24e3b8c9!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
ClamAVWin.Trojan.Hicrazyk-12
KasperskyHEUR:Trojan-Downloader.NSIS.Chindo.gen
BitDefenderTrojan.Downloader.Hicrazyk.A
NANO-AntivirusTrojan.Win32.Dwn.doipwk
AvastNSIS:Adware-MT [PUP]
EmsisoftTrojan.Downloader.Hicrazyk.A (B)
ComodoApplication.Win32.MeinV.BB@59raio
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
SophosTroj/StartP-HV
IkarusTrojan.SuspectCRC
GDataTrojan.Downloader.Hicrazyk.A
MAXmalware (ai score=99)
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Downloader.Hicrazyk.A
ZoneAlarmHEUR:Trojan-Downloader.NSIS.Chindo.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32TrojanDownloader.Chindo
ALYacTrojan.Downloader.Hicrazyk.A
MalwarebytesMalware.AI.3979688624
RisingDownloader.Grinidou!8.488 (CLOUD)
FortinetW32/Agent.NPU!tr.dldr
AVGNSIS:Adware-MT [PUP]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove NSIS:Adware-MT [PUP]?

NSIS:Adware-MT [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment