Malware

Win32/RA-based.NIS removal tips

Malware Removal

The Win32/RA-based.NIS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/RA-based.NIS virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/RA-based.NIS?


File Info:

crc32: 422C7B49
md5: 3266feb35d1eaa9697dd2e000b0ce18c
name: kam.exe
sha1: 9808c7321101e02f1c016c5726fc212ca727a2f7
sha256: f695f5b135b5254122d1c4613b5f470f5f021853d7e03dd82b52be19586d1e2f
sha512: af0609f62a0c0df528ba3b433933825a737f6c0be0345297ee3259598b20180dd950f1309b933174cd61b20d623018421800d85459ca5819fc4471827931c4da
ssdeep: 49152:ycN67XE1hz/zPkQEhc12PEV1Ywc8AWL321ZMihj3NOm+5SyE2hrh4PyxeNr5XaFk:yJoh3UFMV1pA12ihRO5EKq649ZG4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: QEOUZMZKVJ
FileVersion: 1.7.2.1
CompanyName: QEOUZMZKVJ
LegalTrademarks: QEOUZMZKVJ
Comments: QEOUZMZKVJ
ProductName: QEOUZMZKVJQEOUZMZKVJ
FileDescription: QEOUZMZKVJ
Translation: 0x0409 0x04e4

Win32/RA-based.NIS also known as:

BkavHW32.Packed.
DrWebTrojan.StartPage1.58172
MicroWorld-eScanTrojan.GenericKD.41958431
FireEyeTrojan.GenericKD.41958431
CAT-QuickHealTrojan.Scrami
McAfeeArtemis!3266FEB35D1E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055681f1 )
BitDefenderTrojan.GenericKD.41958431
K7GWTrojan ( 0055681f1 )
TrendMicroTROJ_GEN.R002C0GJV19
CyrenW32/Trojan.OVVQ-6022
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.41958431
KasperskyHEUR:Trojan.Win32.Scrami.gen
AlibabaTrojan:Win32/based.e1d7def1
AegisLabTrojan.Win32.Scrami.4!c
RisingTrojan.ScriptRunner/NSIS!1.BD6D (CLASSIC)
Ad-AwareTrojan.GenericKD.41958431
SophosMal/Generic-S
ComodoMalware@#126oio5sjztff
F-SecureHeuristic.HEUR/AGEN.1042347
McAfee-GW-EditionArtemis!Trojan
EmsisoftAdware.Agent (A)
SentinelOneDFI – Malicious PE
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1042347
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2803C1F
ZoneAlarmHEUR:Trojan.Win32.Scrami.gen
MicrosoftTrojan:Win32/Skeeyah.A!MTB
AhnLab-V3PUP/Win32.RL_Agent.R293607
VBA32Trojan.Scrami
ALYacTrojan.Agent.Scrami
MAXmalware (ai score=89)
MalwarebytesBackdoor.Agent
PandaTrj/CI.A
ESET-NOD32Win32/RA-based.NIS
TrendMicro-HouseCallTROJ_GEN.R002C0GJV19
FortinetW32/RA.NIZ!tr
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
Qihoo-360Win32/Trojan.02c

How to remove Win32/RA-based.NIS?

Win32/RA-based.NIS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment