Trojan

Trojan:Win32/Nsisx removal instruction

Malware Removal

The Trojan:Win32/Nsisx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Nsisx virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Nsisx?


File Info:

name: 45940981FE909CC104EC.mlw
path: /opt/CAPEv2/storage/binaries/e315436194fc3393c84aac01a11d3bc646eba90cb6a1a103e60c1774bc7e2b4b
crc32: 57975930
md5: 45940981fe909cc104ec39b580478b4e
sha1: 8e488051c1c83b3d2d907bfe44f091089a1fa02a
sha256: e315436194fc3393c84aac01a11d3bc646eba90cb6a1a103e60c1774bc7e2b4b
sha512: 301f8da8ee665bc1de148f5dc2468702a5d0df20ef73ef80b40dcc09238c6fba93a0ac2e49ed0ebae3cb670e306ee4775878420096c7763127878f0179b2169b
ssdeep: 12288:Tg9mdK89EERUXCS3rDsFYih//SZUnkdovlo1MfxmVISRfwelsIDS5pEA81ZM6:UmdK2naCqrwrh3xkd2x6gelQf2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C7F423197671F0A7DEC44F7023E640768FB46D2826B1604F0B50BE787ABF7429789E1A
sha3_384: 8af91c0d8b787a0d28abf806919bd553ae8526d86e18ff73c81d144a02e09905d8188a88c83e9a3f0be1638c2d0bec55
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2016-07-25 00:55:51

Version Info:

0: [No Data]

Trojan:Win32/Nsisx also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Makoob.4!c
MicroWorld-eScanTrojan.GenericKD.68260698
SkyhighRDN/Generic Downloader.x
McAfeeRDN/Generic Downloader.x
MalwarebytesTrojan.Injector.NSIS
VIPRETrojan.GenericKD.68260698
SangforTrojan.Win32.Injector.Vduq
K7AntiVirusTrojan ( 005a8cc81 )
K7GWTrojan ( 005a8cc81 )
VirITTrojan.Win32.GenusT.DOJN
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Makoob.gen
AlibabaTrojan:Win32/Makoob.91b53fad
AvastNSIS:InjectorX-gen [Trj]
EmsisoftTrojan.GenericKD.68260698 (B)
F-SecureTrojan.TR/Injector.jnnwf
DrWebTrojan.Siggen21.9483
ZillyaTrojan.Makoob.Win32.903
TrendMicroTROJ_GEN.R002C0DB724
Trapminemalicious.high.ml.score
SophosMal/Generic-S
WebrootW32.Trojan.NSISX.Spy
VaristW32/ABTrojan.QJQY-1007
AviraTR/Injector.jnnwf
MAXmalware (ai score=100)
Antiy-AVLTrojan/NSIS.Injector.bzg
KingsoftWin32.Troj.Generic.v
XcitiumMalware@#34l9dhnlum21q
ArcabitTrojan.Generic.D411935A
ViRobotTrojan.Win.Z.Injector.758264
ZoneAlarmHEUR:Trojan.Win32.Makoob.gen
MicrosoftTrojan:Win32/Nsisx
GoogleDetected
AhnLab-V3Downloader/Win.GuLoader.C5457569
ALYacTrojan.GenericKD.68260698
VBA32Trojan.LokiBot
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DB724
TencentWin32.Trojan.FalseSign.Psmw
YandexTrojan.Igent.b0vPch.3
FortinetNSIS/Injector.CR4P!tr
AVGNSIS:InjectorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Nsisx?

Trojan:Win32/Nsisx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment