Trojan

How to remove “Trojan:Win32/NukeSped.RS!MSR”?

Malware Removal

The Trojan:Win32/NukeSped.RS!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/NukeSped.RS!MSR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

How to determine Trojan:Win32/NukeSped.RS!MSR?


File Info:

name: 8910BDAAA6D3D40E9F60.mlw
path: /opt/CAPEv2/storage/binaries/82d33a67c68f7c476a9ac1e960abc6a911f797446a2c24f0e13b92af1eb385b8
crc32: F0825A5D
md5: 8910bdaaa6d3d40e9f60523d3a34f914
sha1: c48c21fe7c6f9f6e03fe91253e79a65bd667bbaa
sha256: 82d33a67c68f7c476a9ac1e960abc6a911f797446a2c24f0e13b92af1eb385b8
sha512: f9dd1afe6ba2373793c32b840907a8549c222a70ec9c045ece4f0b6e1ce9a3b1e2d43e6ab47b35266d91741155ab533f688b63db95093971726b0d6910a822c6
ssdeep: 24576:thomwVzBwijGuyB2iLAEgYfgU6MlhU1pLSG+RYRqk4FxAxkKPHzO/X1o:G/DQoZVMAMJ1KPHzCX1o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13455BF53FB8249B2E8C6017850E75B7F4E36AE10433AD9D38B9129658D326D06B3F3D9
sha3_384: 4f765d9536d22da598135eca4831eb35631a070b4b26cac8380a73069279a2e0384223150af5332334dc74c309ef9a2b
ep_bytes: e88b0b0000e97afeffffcccc518d4c24
timestamp: 2019-05-03 01:10:58

Version Info:

0: [No Data]

Trojan:Win32/NukeSped.RS!MSR also known as:

LionicTrojan.Win32.Generic.4!c
CAT-QuickHealTrojan.Wimata.S15413984
McAfeeGenericRXJI-FO!8910BDAAA6D3
CylanceUnsafe
SangforTrojan.Win32.TFlower.IOC
K7AntiVirusTrojan ( 0056ab271 )
AlibabaTrojan:Win32/NukeSped.2449cb89
K7GWTrojan ( 0056ab271 )
Cybereasonmalicious.aa6d3d
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/NukeSped.GB
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.37147284
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.GenericKD.37147284
TencentWin32.Trojan.Generic.Dzjk
Ad-AwareTrojan.GenericKD.37147284
EmsisoftTrojan.GenericKD.37147284 (B)
F-SecureTrojan.TR/NukeSped.B
DrWebTrojan.Siggen8.64917
ZillyaTrojan.NukeSped.Win32.238
TrendMicroBKDR_DACLS.ZJHA-A
McAfee-GW-EditionGenericRXJI-FO!8910BDAAA6D3
FireEyeGeneric.mg.8910bdaaa6d3d40e
SophosMal/Generic-R + Troj/Agent-BFQM
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.dhuny
WebrootW32.Trojan.GenKD
AviraTR/NukeSped.B
Antiy-AVLTrojan/Win32.Occamy
MicrosoftTrojan:Win32/NukeSped.RS!MSR
ArcabitTrojan.Generic.D236D294
ViRobotTrojan.Win32.S.Agent.1396736.AJ
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.37147284
TACHYONBackdoor/W32.Dacls.1396736
AhnLab-V3Trojan/Win32.MalPacked.C3529823
VBA32BScope.Trojan.Zpevdo
ALYacTrojan.Agent.1745408
MAXmalware (ai score=94)
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallBKDR_DACLS.ZJHA-A
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.Agent!3rRemB0fhK0
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Mata.F914!tr
BitDefenderThetaGen:NN.ZexaF.34638.vvW@a0x4RYhi
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/NukeSped.RS!MSR?

Trojan:Win32/NukeSped.RS!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment