Trojan

Trojan-Dropper.Win32.NSIS.adug removal tips

Malware Removal

The Trojan-Dropper.Win32.NSIS.adug is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.NSIS.adug virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid

How to determine Trojan-Dropper.Win32.NSIS.adug?


File Info:

name: 3408D9F511137BD12F11.mlw
path: /opt/CAPEv2/storage/binaries/637ce88a668b18b7c359324955fce5829ab137477d9c5ffcabafc20ef93f7d45
crc32: 212B5226
md5: 3408d9f511137bd12f116856e7a1fdd3
sha1: c1f83b86c2b2b83dd9bc29d8123b1434bcb50ecb
sha256: 637ce88a668b18b7c359324955fce5829ab137477d9c5ffcabafc20ef93f7d45
sha512: 5c13086712d05c73ee23f65fed536f0ec60630a1d7330241fc1edf9df57f633e9c91227c795b9d881085ef625e3ca5d2603618dae96fdc52cc3866c7dcbe720c
ssdeep: 12288:Y0gVJpqYymyxhZy+cYWhpIKJpUbjYIczVmjuldONAvA7KGbNuw:jUC9ThETrh3JSudONgA7XU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B915232A7BD89121EAB00532EAF29016D17AFC230C7145DB72C5FFDE3E70951895BB62
sha3_384: 0c55220591d5744c5bdcb579e7e1106d7643acf20092a06051ef632e9ac7bd894818bc3f0050b98ca7227b797b2d501f
ep_bytes: 81ecd4020000535556576a2033ed5e89
timestamp: 2012-02-24 19:20:04

Version Info:

FileDescription:
FileVersion: 3, 3, 6, 1
CompiledScript: AutoIt v3 Script: 3, 3, 6, 1
Translation: 0x0809 0x04b0

Trojan-Dropper.Win32.NSIS.adug also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.AutoIT.10
ClamAVWin.Ransomware.Sodinokibi-9887839-0
FireEyeGeneric.mg.3408d9f511137bd1
McAfeeGenericR-JHR!3408D9F51113
CylanceUnsafe
ZillyaAdware.DomaIQ.Win32.77
CyrenW32/ABRisk.VNQY-4675
ESET-NOD32a variant of Win32/TrojanDownloader.VB.QNP
APEXMalicious
KasperskyTrojan-Dropper.Win32.NSIS.adug
BitDefenderGen:Trojan.Heur.AutoIT.10
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Trojan.Heur.AutoIT.10
EmsisoftGen:Trojan.Heur.AutoIT.10 (B)
VIPREGen:Trojan.Heur.AutoIT.10
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
GDataGen:Trojan.Heur.AutoIT.10
WebrootW32.Boaxxe.Gen
ArcabitTrojan.Heur.AutoIT.10
MicrosoftTrojan:Win32/Bluteal.B!rfn
Acronissuspicious
ALYacGen:Trojan.Heur.AutoIT.10
MAXmalware (ai score=82)
VBA32TrojanDropper.yep
MalwarebytesMalware.Heuristic.1003
FortinetW32/PossibleThreat
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.511137
PandaTrj/Genetic.gen

How to remove Trojan-Dropper.Win32.NSIS.adug?

Trojan-Dropper.Win32.NSIS.adug removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment