Trojan

Trojan:Win32/Nsisinject!mclg removal

Malware Removal

The Trojan:Win32/Nsisinject!mclg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Nsisinject!mclg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Trojan:Win32/Nsisinject!mclg?


File Info:

name: 3461688B684C14BFA1B8.mlw
path: /opt/CAPEv2/storage/binaries/5869ff09468b1aafa73c0a8fa15c953995495aa7144114003fdc4743860639ad
crc32: 355D6361
md5: 3461688b684c14bfa1b81f1a110254e4
sha1: 70269a15f2b27f2a3a33a4028d7aeb2e1094db58
sha256: 5869ff09468b1aafa73c0a8fa15c953995495aa7144114003fdc4743860639ad
sha512: bc1ecb387ca68cf57fa1264ad6567ddca62bbf87f97362a66d3755e48496afe8f9013186dc7d03bec6c5201f0c3906715ec8a00b16bc1fa1d394256692913b93
ssdeep: 6144:rGiG8cKLnPjzfoNvzfe67vOpnNczXDErvIJHOZabXKtyYov27XebMWHsdjE:SdKXzr6enNczXQrIJHOsbyyHFxsdE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192642302DAD2A5BDC4E0883458B75A79EEF7B4B4491807039B703EFA7F164AB41472B3
sha3_384: 5e92d5801f3391fd2c6a70175b0eada35f9fcb01deba96cf6728eb170dbbdd4dda08e1aa02c5b5e1dadf306bde825ce5
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Trojan:Win32/Nsisinject!mclg also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.60377
MicroWorld-eScanTrojan.GenericKD.38165806
FireEyeTrojan.GenericKD.38165806
McAfeeRDN/GenericAC
MalwarebytesMalware.AI.4232808380
SangforTrojan.Win32.Sabsik.FL
K7AntiVirusTrojan ( 0058b4401 )
AlibabaTrojanSpy:Win32/Lokibot.e380b483
K7GWTrojan ( 0058b4401 )
Cybereasonmalicious.b684c1
CyrenW32/Injector.AQQ.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector_AGen.DM
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.aoarl
BitDefenderTrojan.GenericKD.38165806
SUPERAntiSpywareTrojan.Agent/Gen-Siggen
AvastWin32:PWSX-gen [Trj]
EmsisoftTrojan.GenericKD.38165806 (B)
ComodoMalware@#3388ug0zlx8qt
TrendMicroTROJ_FRS.VSNTL321
McAfee-GW-EditionRDN/GenericAC
SophosMal/Generic-S
IkarusTrojan.NSIS.Agent
AviraTR/Redcap.skmgm
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Nsisinject!mclg
ViRobotTrojan.Win32.Z.Injector.329536.A
GDataWin32.Trojan-Stealer.FormBook.HPAJ1I
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4807393
VBA32TrojanSpy.Noon
ALYacTrojan.GenericKD.38165806
MAXmalware (ai score=88)
CylanceUnsafe
TrendMicro-HouseCallTROJ_FRS.VSNTL321
RisingTrojan.Injector_AGen!8.12CEE (CLOUD)
FortinetW32/Injector.EQTC!tr
WebrootW32.Trojan.Gen
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Nsisinject!mclg?

Trojan:Win32/Nsisinject!mclg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment