Spy

Spyware.PasswordStealer.NSIS removal instruction

Malware Removal

The Spyware.PasswordStealer.NSIS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.PasswordStealer.NSIS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Spyware.PasswordStealer.NSIS?


File Info:

crc32: 787CEA07
md5: ba562ff157147e6191afce2e78b56ea2
name: BA562FF157147E6191AFCE2E78B56EA2.mlw
sha1: 682d117591198af1d7dd792586635250946a543a
sha256: a895a68bb13034029be4ec32611db4b430bb8287449babbc4946eb2fe5044ffd
sha512: 7b156ac6770c2117d35edd578aabdb838683e88dabb3d80b7247d93f6c5ffe29a3daa6921e168dcd2f0ed2642c91ec1b78e353435f4bf288c560ab87f838a57c
ssdeep: 6144:8Qq+n0PMRAsM/uzy6AS2faCE5vAr+NAcmavaySkx7QVjfEUgfBKF5FRi+QZQp:TlHzy6ASzH5or+NAvCaySk2jfCKnFjp
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Spyware.PasswordStealer.NSIS also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.Loader.834
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Ninjector.J.gen!Camelot
SymantecTrojan Horse
ESET-NOD32MSIL/Spy.Agent.AES
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
BitDefenderTrojan.GenericKD.37029517
MicroWorld-eScanTrojan.GenericKD.37029517
Ad-AwareTrojan.GenericKD.37029517
SophosMal/Generic-S + Troj/Tesla-KV
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeTrojan.GenericKD.37029517
EmsisoftTrojan.GenericKD.37029517 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.AgentTesla.vxbhx
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Stelega.KZ!MTB
GDataMSIL.Trojan-Stealer.AgentTesla.09J42O
AhnLab-V3Malware/Win.Generic.C4511913
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=85)
MalwarebytesSpyware.PasswordStealer.NSIS
TrendMicro-HouseCallTROJ_GEN.F0D1C00F321
RisingTrojan.Injector/NSIS!1.D6F5 (CLASSIC)
IkarusWin32.SuspectCrc
FortinetNSIS/Ninjector.J!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Spyware.PasswordStealer.NSIS?

Spyware.PasswordStealer.NSIS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment