Trojan

Trojan.NSIS.Androm.6 (B) information

Malware Removal

The Trojan.NSIS.Androm.6 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.NSIS.Androm.6 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • PlugX
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.NSIS.Androm.6 (B)?


File Info:

crc32: D4ACEA8A
md5: eb2de69ebb0cbaee4b3fe5656c4e16e6
name: EB2DE69EBB0CBAEE4B3FE5656C4E16E6.mlw
sha1: 0fb2bb34ca97eea804f1b1c7706855720d2e352e
sha256: 3c4da372c91ad509b6adc8c21858792b8fe384ababd2fdb13fdc39dfbe836701
sha512: 3415f6b0c6d32447c6e407af02f31d6ea12bec18cf1f700aae1c5cd39a6edf831d6e3a1747da647e1fafeab1650ef170591f15fd1cc677060dfbcdfe3e3890cf
ssdeep: 6144:0n/L+jh4LS+WUAovf97HD9NaN2kXf/xg7gHuQsaW9Uumfj8iT:6Oh4tCQpjGN/Xf/IgHu9aW95mfj82
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.NSIS.Androm.6 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Click3.25793
MicroWorld-eScanTrojan.NSIS.Androm.6
CAT-QuickHealRansom.Cerber.A
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.845
SangforRiskware.Win32.Agent.ky
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ebb0cb
SymantecRansom.Cerber
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Zerber.gen
BitDefenderTrojan.NSIS.Androm.6
NANO-AntivirusTrojan.Win32.DKVA.eljcvj
ViRobotTrojan.Win32.Cerber.331246
TencentWin32.Trojan.Generic.Akfd
SophosMal/Generic-R + Mal/Cerber-Z
ComodoMalware@#1inzv351eeg3h
BitDefenderThetaGen:NN.ZedlaF.34628.gu8@aOdyGfbi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Cerber-NS3
McAfee-GW-EditionGenericRXGB-RI!2FD5EA80AD0B
FireEyeGeneric.mg.eb2de69ebb0cbaee
EmsisoftTrojan.NSIS.Androm.6 (B)
WebrootW32.Trojan.Ransom
AviraHEUR/AGEN.1111189
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Cerber
GDataZum.Androm.1
AhnLab-V3Trojan/Win32.Cerber.R194711
McAfeeArtemis!EB2DE69EBB0C
MAXmalware (ai score=86)
VBA32Trojan.Sod
PandaTrj/CI.A
TrendMicro-HouseCallMal_Cerber-NS3
RisingRansom.Enestedel!8.E513 (CLOUD)
YandexTrojan.Injector!css2/zBVW4I
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DKTT!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Trojan.Ransom.9da

How to remove Trojan.NSIS.Androm.6 (B)?

Trojan.NSIS.Androm.6 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment