Trojan

Trojan.Injector.NSIS.Generic removal guide

Malware Removal

The Trojan.Injector.NSIS.Generic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Injector.NSIS.Generic virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Injector.NSIS.Generic?


File Info:

crc32: 00FC195A
md5: 4d394253efaddaea8cec658f6bf05016
name: signed.exe
sha1: 723101b79f8e7abe0d092a39055eaf933b680791
sha256: a216a9f03c304596c8cfaf296504f5ae4cb386839d4a00cb190c3b2a1e44582b
sha512: ec6a7b1edb0d6ddbec5fb6d6ffcb50d66d26a5fde0e937d69cf747a8c538205736e32a7bf791dc657e03347c9b895f0bd4e099745235846c5eaa3459af2430a3
ssdeep: 98304:Bfc+aYDb3pD6qFmqaksTwzloD+4YEH5gOI9r6/x9JI:FvFDb8uN0THKDEHG9g9JI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: all rights reserved
FileVersion: 1.4.7.1
CompanyName: lib pack archive march
LegalTrademarks: symantec company all rights
Comments: lib pack archive march
ProductName: lib pack 2020
Translation: 0x0409 0x04e4

Trojan.Injector.NSIS.Generic also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.42847724
FireEyeTrojan.GenericKD.42847724
Qihoo-360Win32/Trojan.Dropper.45c
McAfeeArtemis!4D394253EFAD
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agent.b!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.42847724
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Score-6931191-0
GDataTrojan.GenericKD.42847724
KasperskyHEUR:Trojan-Dropper.Win32.Agent.gen
AlibabaTrojanDropper:Win32/Generic.6ba34c1e
Ad-AwareTrojan.GenericKD.42847724
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1046052
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.42847724 (B)
AviraHEUR/AGEN.1046052
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28DCDEC
ZoneAlarmHEUR:Trojan-Dropper.Win32.Agent.gen
MicrosoftTrojan:Win32/Skeeyah!MTB
ALYacTrojan.GenericKD.42847724
MAXmalware (ai score=82)
MalwarebytesTrojan.Injector.NSIS.Generic
PandaTrj/CI.A
ESET-NOD32PowerShell/TrojanDropper.Agent.CR
TrendMicro-HouseCallTROJ_GEN.R002H0CCG20
RisingTrojan.ScriptRunner/NSIS!1.BD6D (CLASSIC)
FortinetNSIS/Agent.C!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Injector.NSIS.Generic?

Trojan.Injector.NSIS.Generic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment