Malware

NSIS:ConvertAd-P [Adw] removal instruction

Malware Removal

The NSIS:ConvertAd-P [Adw] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:ConvertAd-P [Adw] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

www.download-servers.com

How to determine NSIS:ConvertAd-P [Adw]?


File Info:

crc32: A8D9FCFE
md5: 925d6e611a57a22476644823a55d1ad3
name: 925D6E611A57A22476644823A55D1AD3.mlw
sha1: 5949a242d3479c0636099f2abffb6be0e7829d67
sha256: 237d51bda8fd406981516f7a0380ce9d2590248c4b04567e059d5887035ca0fd
sha512: a37ae2310c40e1c018ac4d07eee8572947aa22f866d36d47f6eb72956ab1fc80af32cadba469ceed518e1102b89eea0117b8cb6d64cf3e3c2357326fafd9ebcc
ssdeep: 3072:ogXdZt9P6D3XJ7CzOsm4VOYZLPHL7huN9VgS9o4sXo4sm:oe34YzXVOEzrUBgQ8p
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

NSIS:ConvertAd-P [Adw] also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.ConvertAd.2!c
DrWebTrojan.DownLoader14.31286
CynetMalicious (score: 99)
ALYacDropped:Trojan.GenericKD.12041023
CylanceUnsafe
ZillyaAdware.ConvertAD.Win32.62859
SangforAdware.Win32.ConvertAd.P
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/ConvertAd.79edc9cb
Cybereasonmalicious.11a57a
ESET-NOD32a variant of Win32/Adware.ConvertAd.QS
APEXMalicious
AvastNSIS:ConvertAd-P [Adw]
Kasperskynot-a-virus:HEUR:AdWare.NSIS.ConvertAd.heur
BitDefenderDropped:Trojan.GenericKD.12041023
MicroWorld-eScanDropped:Trojan.GenericKD.12041023
TencentWin32.Adware.Convertad.Hrez
Ad-AwareDropped:Trojan.GenericKD.12041023
SophosGeneric ML PUA (PUA)
VIPREConvertAd
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.cc
FireEyeDropped:Trojan.GenericKD.12041023
EmsisoftDropped:Trojan.GenericKD.12041023 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.ConvertAd.agng
WebrootW32.Downloader.Gen
AviraHEUR/AGEN.1144552
MicrosoftTrojan:Win32/Occamy.C
SUPERAntiSpywarePUP.DotDo/Variant
GDataDropped:Trojan.GenericKD.12041023
McAfeeArtemis!925D6E611A57
MAXmalware (ai score=82)
VBA32Adware.ConvertAd
FortinetRiskware/ConvertAd
AVGNSIS:ConvertAd-P [Adw]
Paloaltogeneric.ml

How to remove NSIS:ConvertAd-P [Adw]?

NSIS:ConvertAd-P [Adw] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment