PUA

About “NSIS:Crossrider-Z [PUP]” infection

Malware Removal

The NSIS:Crossrider-Z [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Crossrider-Z [PUP] virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
p9qf5evq62d-sbn457z6.netdna-ssl.com
cwv5ufu0fn-sbn457z6.netdna-ssl.com
a.tomx.xyz
edgedl.me.gvt1.com

How to determine NSIS:Crossrider-Z [PUP]?


File Info:

crc32: 99C17BF6
md5: 4bf8bc328115ed3539226a700a7e777d
name: 4BF8BC328115ED3539226A700A7E777D.mlw
sha1: 5752d4e24288da9b7e07c72c0d6351b59e2b8a2c
sha256: 2d7b516f8b43aed40a331539db6f1ca8bd5c2c0047c42fdc97e1fa3281a7f4ca
sha512: bee8a4c1d97bb3ac305f0a42b44bb78019ca9dce0f31bdb7c64022ca27339af5f827bf358184d13197819f7c016021f6962f6796ee6cff447e619ef2aa8d61e5
ssdeep: 24576:bTA0JZIvE6V+k/PW0AjLGJSTVAwf8mUBWirUAUXnNZ2HUOxg63jj:XwMqXQxTiwfBUBtr4XnNZ20n63jj
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

FileVersion: 2.8.9507.666
ProductVersion: 2.8.9507.666
Translation: 0x0409 0x04e4

NSIS:Crossrider-Z [PUP] also known as:

LionicRiskware.NSIS.Agent.1!c
Elasticmalicious (high confidence)
DrWebTrojan.Crossrider.38087
CynetMalicious (score: 100)
CylanceUnsafe
SangforPUP.Win32.SpeedBit.8
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaDownloader:Win32/SpeedBit.c0c18da7
Cybereasonmalicious.24288d
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/SpeedBit.G potentially unwanted
APEXMalicious
AvastNSIS:Crossrider-Z [PUP]
Kasperskynot-a-virus:Downloader.NSIS.Agent.ri
NANO-AntivirusTrojan.Nsis.Agent.dmgbnp
ViRobotAdware.Crossrider.1279061
SophosGeneric PUA FH (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.tc
FireEyeGeneric.mg.4bf8bc328115ed35
SentinelOneStatic AI – Malicious PE
WebrootW32.Downloader.Gen
AviraADWARE/Adware.Gen
Antiy-AVLTrojan/Generic.ASMalwNS.32A6
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitPUP.Adware.Shopro
GDataNSIS.Application.Crypted.C
AhnLab-V3PUP/Win32.CrossRider.R157137
McAfeeArtemis!4BF8BC328115
VBA32Adware.Agent
TrendMicro-HouseCallTROJ_GEN.R002H07J121
AVGNSIS:Crossrider-Z [PUP]
Paloaltogeneric.ml

How to remove NSIS:Crossrider-Z [PUP]?

NSIS:Crossrider-Z [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment