Malware

Should I remove “NSIS:Pbot-A [Trj]”?

Malware Removal

The NSIS:Pbot-A [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Pbot-A [Trj] virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.google-analytics.com

How to determine NSIS:Pbot-A [Trj]?


File Info:

crc32: E7B7129C
md5: c12725e9c4f069c4552ae529223cb470
name: C12725E9C4F069C4552AE529223CB470.mlw
sha1: 53f23346c9795b070f846f51421ce80215b6ea63
sha256: 3c20e3e791f6acf4d1be092bd86d7e3216efb1ed0a1df93b7f2586a84ab6a2c4
sha512: 5311672c34aa26d2d679236c441e344709c2aab707ac26ce7fc7b00f195cfe43a57843a15e0efe32cf5da8a9cb2d081ed5f03498d01fa0fe44a977674da0500a
ssdeep: 24576:2mnfnNOhSeDWGUIgKQsDGK8ILc2qKtutrUN0+TKKvG/5auSs4+rF+supDieOo:pFOU/ff/IA2ZutrlPF4GtupDieOo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

NSIS:Pbot-A [Trj] also known as:

K7AntiVirusTrojan ( 0056e5201 )
LionicAdware.Win32.Generic.2!c
DrWebPython.Packed.3
CynetMalicious (score: 99)
ALYacAdware.GenericKD.30822366
CylanceUnsafe
ZillyaAdware.PBot.Win32.36
SangforAdware.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/Python.d8779315
K7GWTrojan ( 0056e5201 )
Cybereasonmalicious.9c4f06
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
AvastNSIS:Pbot-A [Trj]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderAdware.GenericKD.30822366
NANO-AntivirusRiskware.Win32.Mlw.fgibgy
MicroWorld-eScanAdware.GenericKD.30822366
TencentWin32.Adware.Generic.Sunf
Ad-AwareAdware.GenericKD.30822366
SophosGeneric PUA FD (PUA)
ComodoApplicUnwnt@#aotp9n2klhwa
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.c12725e9c4f069c4
EmsisoftAdware.GenericKD.30822366 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1107062
MicrosoftTrojan:Win32/Azorult!ml
ArcabitAdware.Generic.D1D64FDE
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataAdware.GenericKD.30822366
AhnLab-V3PUP/Win32.PBot.R226081
McAfeeArtemis!C12725E9C4F0
MAXmalware (ai score=61)
VBA32Trojan.Wacatac
MalwarebytesTrojan.Agent.RU
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CGQ21
YandexPUA.Agent!oJBmf/x0f8E
MaxSecureWin.MxResIcn.Heur.Gen
AVGNSIS:Pbot-A [Trj]
Paloaltogeneric.ml

How to remove NSIS:Pbot-A [Trj]?

NSIS:Pbot-A [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment