Ransom

Ransom.Shade.NSIS (file analysis)

Malware Removal

The Ransom.Shade.NSIS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Shade.NSIS virus can do?

  • Anomalous binary characteristics

How to determine Ransom.Shade.NSIS?


File Info:

crc32: 86B4090B
md5: 3ed59ddb68669b46a5af1570a95f7827
name: 3ED59DDB68669B46A5AF1570A95F7827.mlw
sha1: 4af0fa3a657fc80e4afb15b1f11513fd9cc3aad5
sha256: 9229c89411e47d19e9173f086d0949765e633dbee851a24314a3d34a598bc2f1
sha512: f62362e87b340524ce0179826c6f7f5756e12a53dca6615df85a0c4bb53d7d8c1118c4f68ada46ba001b56552e44c750198b52850c9336c88e94801e3db8b306
ssdeep: 6144:3hRiHuv5aSI6VMnEy1lJxfxfq3e+u+5ZHk74YDKkcN9rvq:xIHuv0sip+rXkxKXN9rS
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: RVM
FileVersion: 0.6.7
CompanyName: RVM
LegalTrademarks: RVM
Comments: This installation was built with NSIS.
ProductName: SMPlayer
FileDescription: SMPlayer for Windows
Translation: 0x0409 0x04e4

Ransom.Shade.NSIS also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005177c61 )
Elasticmalicious (high confidence)
ALYacTrojan.Ransom.BXA
CylanceUnsafe
SangforRansom.Win32.Shade.gen
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Injector.88d26427
K7GWTrojan ( 005177c61 )
Cybereasonmalicious.b68669
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of NSIS/Injector.WG
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Shade.gen
BitDefenderTrojan.Ransom.BXA
NANO-AntivirusTrojan.Nsis.AD.etolfo
MicroWorld-eScanTrojan.Ransom.BXA
TencentWin32.Trojan.Generic.Lpbx
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeTrojan.Ransom.BXA
EmsisoftTrojan.Ransom.BXA (B)
WebrootW32.Trojan.Gen
MicrosoftTrojan:Win32/Occamy.C92
AegisLabTrojan.Win32.Shade.4!c
GDataTrojan.Ransom.BXA
AhnLab-V3Trojan/Win32.Globeimposter.R209326
McAfeeRansom-GlobeImp!3ED59DDB6866
MAXmalware (ai score=81)
MalwarebytesRansom.Shade.NSIS
PandaTrj/CI.A
IkarusTrojan.NSIS.Injector
FortinetW32/Injector.XG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom.Shade.NSIS?

Ransom.Shade.NSIS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment