Malware

Win32/PSW.Legendmir.NHB removal instruction

Malware Removal

The Win32/PSW.Legendmir.NHB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/PSW.Legendmir.NHB virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32/PSW.Legendmir.NHB?


File Info:

crc32: 1E026475
md5: 41585b26bedef25293adb0b5858a41f3
name: jsy.dat
sha1: 9193b7761b3c292a033d4cc5b5733537a7e0eddd
sha256: 479d02a43572bd269b473d80ee6ec57f9ca1a863d2fe20eed7ebbd81b9c34164
sha512: 28726745e2ef5aabe5ed336b1f860290a6f62cf0b8bbd40cf25746baafa4a990a8e5b4f33ccbaf0a8f56bb2c2f03fd99335f82361b250cd2ad291e0d78fe4cce
ssdeep: 3072:+M5OAQmIM5QTETX/8mEXJhBgYC5PNNYRrKFYXHkj5olvXK/62H9o1:+M5LeTW0f7BgYsgKYe5ol/K/XH9U
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2003-2004
InternalName:
FileVersion: 7, 7, 5, 0
CompanyName:
ProductName: x53cax65f6x96e8PKx7248
ProductVersion: 7, 7, 5, 0
FileDescription: x53cax65f6x96e8PKx7248(http://www.mir666.com)
OriginalFilename: JSY.EXE
Translation: 0x0804 0x04b0

Win32/PSW.Legendmir.NHB also known as:

DrWebTrojan.StartPage.21556
FireEyeGeneric.mg.41585b26bedef252
CAT-QuickHealTrojan.IGENERIC
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusPassword-Stealer ( 0055e3dc1 )
K7GWPassword-Stealer ( 0055e3dc1 )
Cybereasonmalicious.61b3c2
F-ProtW32/Backdoor2.HTRC
TotalDefenseWin32/Lemir.AAF
APEXMalicious
ClamAVWin.Trojan.Agent-512422
AlibabaTrojanPSW:Win32/Legendmir.452f6aad
NANO-AntivirusTrojan.Win32.Legendmir.ibir
ViRobotTrojan.Win32.PSWLmir.171520
ComodoMalware@#19gjdy8vj44fr
ZillyaTrojan.Legendmir.Win32.346
McAfee-GW-EditionGeneric.emy
Trapminemalicious.moderate.ml.score
IkarusTrojan-PWS.Win32.Lmir.aqr
CyrenW32/Backdoor.PLBS-9330
WebrootW32.Malware.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan[GameThief]/Win32.Lmir
MicrosoftTrojan:Win32/Bumat!rfn
AhnLab-V3Unwanted/Win32.HackTool.R86801
McAfeeGeneric.emy
PandaTrj/Lineage.HZT
ESET-NOD32a variant of Win32/PSW.Legendmir.NHB
YandexTrojan.PWS.Prast!c7vI4hAtRco
eGambitUnsafe.AI_Score_99%
FortinetMalware_fam.gw
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.2588.susgen

How to remove Win32/PSW.Legendmir.NHB?

Win32/PSW.Legendmir.NHB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment