Ransom Trojan

What is “Trojan-Ransom.NSIS.MyxaH.qvd”?

Malware Removal

The Trojan-Ransom.NSIS.MyxaH.qvd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.NSIS.MyxaH.qvd virus can do?

  • Reads data out of its own binary image
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.NSIS.MyxaH.qvd?


File Info:

crc32: 0E3ABF9E
md5: af4dfe4dfc56d5d47b7cd809ced33ac2
name: AF4DFE4DFC56D5D47B7CD809CED33AC2.mlw
sha1: dd637e329da7b57c9cec8c8db76472ea0a821b5e
sha256: 398ca6185ae0f6ac45e9d9717104fae5aa83b33089e359bcd7b760f09d88e489
sha512: 311928a6ccb2d12790b8acfcb6f2f5de5bb426333a96eeca78e803ec5b8db09d34c1cb9f6ba02008823998bb5b687a979a2217f5a8cccb72647ec9058950bc15
ssdeep: 12288:7B3qiV1uWDwU8FE4pj7u2japEWkNUwEBEl6g/gK2UrFewbJt8dONv:7B6iaWDwA4vZCEWHGEWgwFewlWd
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Ransom.NSIS.MyxaH.qvd also known as:

BkavW32.AIDetect.malware1
LionicTrojan.NSIS.MyxaH.j!c
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.30425412
CylanceUnsafe
AlibabaRansom:Win32/MyxaH.0cdb0556
Cybereasonmalicious.dfc56d
BaiduNSIS.Trojan-Dropper.Adware.a
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/TrojanDropper.Addrop.B
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Adware.Faww-9848112-0
KasperskyTrojan-Ransom.NSIS.MyxaH.qvd
BitDefenderTrojan.GenericKD.30425412
MicroWorld-eScanTrojan.GenericKD.30425412
TencentNsis.Trojan.Myxah.Lort
Ad-AwareTrojan.GenericKD.30425412
SophosMal/Generic-S
ComodoMalware@#2i45s5lbz2h27
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_MyxaH.R002C0PH421
McAfee-GW-EditionBehavesLike.Win32.Playtech.dc
FireEyeGeneric.mg.af4dfe4dfc56d5d4
EmsisoftTrojan.GenericKD.30425412 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1127162
eGambitUnsafe.AI_Score_96%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.30425412
McAfeeArtemis!AF4DFE4DFC56
MAXmalware (ai score=64)
PandaTrj/CI.A
TrendMicro-HouseCallRansom_MyxaH.R002C0PH421
IkarusPUA.SWUpdater
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HoMASZsA

How to remove Trojan-Ransom.NSIS.MyxaH.qvd?

Trojan-Ransom.NSIS.MyxaH.qvd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment