Trojan

TrojanDownloader:Win32/Nystprac.A malicious file

Malware Removal

The TrojanDownloader:Win32/Nystprac.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Nystprac.A virus can do?

  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDownloader:Win32/Nystprac.A?


File Info:

crc32: EAB5A027
md5: e58319e520f863376401863669881bf4
name: E58319E520F863376401863669881BF4.mlw
sha1: 31f9d65ecf7b6a2010ad59e8a58c3d0a7084dd28
sha256: 300b09dbb4ae19a444102c6347b02495c9b081fde5796ad61fd7dc096fc5d6d1
sha512: e8c55b52675f76378085421f6ffd57d2ab811dca84b223b9f652eb36b7be7ddfa18796c8248304ba2db8d34601a7d034cc87c82a807abe0c01511a6716932c1a
ssdeep: 384:4I4ul1d4WTk9GRWFRN+zTnpRfXTUyOmcZ5sYawI7JReeM2dGoth5JNNzFwhhifW:4I4mFaGU5KTmmisTPNLdGotn3whJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Nystprac.A also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Gh0stRAT-9854656-0
ALYacGen:Variant.Ulise.135793
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Ulise.135793
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.CQX
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Inject.chipuz
MicroWorld-eScanGen:Variant.Ulise.135793
Ad-AwareGen:Variant.Ulise.135793
SophosMal/PePatch-K
ComodoTrojWare.Win32.Farfli.CQ@7y93vk
BitDefenderThetaGen:NN.ZexaF.34684.byY@aulcBCoi
McAfee-GW-EditionPacked-MZ!E58319E520F8
FireEyeGeneric.mg.e58319e520f86337
EmsisoftGen:Variant.Ulise.135793 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
eGambitPE.Heur.InvalidSig
MicrosoftTrojanDownloader:Win32/Nystprac.A
ArcabitTrojan.Ulise.D21271
GDataGen:Variant.Ulise.135793
Acronissuspicious
McAfeePacked-MZ!E58319E520F8
MAXmalware (ai score=84)
VBA32Backdoor.Farfli
MalwarebytesMalware.AI.521088740
RisingBackdoor.Zegost!8.177 (TFE:1:v1b0qrY80QM)
YandexTrojan.GenAsa!jyx+fvnRphc
FortinetW32/SERVSTART.D!tr

How to remove TrojanDownloader:Win32/Nystprac.A?

TrojanDownloader:Win32/Nystprac.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment