Ransom

How to remove “Generic.Ransom.Nemty.26C4E7C4”?

Malware Removal

The Generic.Ransom.Nemty.26C4E7C4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Nemty.26C4E7C4 virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to execute a powershell command with suspicious parameter/s
  • A process created a hidden window
  • Performs some HTTP requests
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Network activity contains more than one unique useragent.
  • Writes a potential ransom message to disk
  • Clears Windows events or logs
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.myexternalip.com
ocsp.pki.goog
crl.pki.goog
crls.pki.goog
nemty10.hk

How to determine Generic.Ransom.Nemty.26C4E7C4?


File Info:

crc32: 074CA013
md5: 7fbd8ffe4b9e08068c8d4b6919c1fc6d
name: 7FBD8FFE4B9E08068C8D4B6919C1FC6D.mlw
sha1: dceb61519fed6fadd58d17d46c61607ad680678c
sha256: 8e056ccffad1f5315a38abf14bcd3a7b662b440bda6a0291a648edcc1819eca6
sha512: 2c3f3cdcfd704e0b504d27c139d229274e989445dc10e0170b569f8d06f446688548b4ef0f63c089a611b1d10c10daf48f9c6a0dabb87d10fc59e403cb511759
ssdeep: 1536:AEDvH/uk7mU3TLBsrZ6ahTQKWTC1vkmM0eRYVYgQxC2evq:AELfuKv3TL+UahUMTMV4YgQxC2evq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Nemty.26C4E7C4 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00556c621 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.30812
CynetMalicious (score: 100)
CAT-QuickHealRansom.Nemty.S13913777
ALYacTrojan.Ransom.Nemty
CylanceUnsafe
ZillyaTrojan.Zenpak.Win32.1573
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Genasom.ali1000102
K7GWTrojan ( 00556c621 )
Cybereasonmalicious.e4b9e0
SymantecDownloader
ESET-NOD32a variant of Win32/Filecoder.Nemty.C
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
KasperskyHEUR:Trojan.Win32.Zenpak.vho
BitDefenderGeneric.Ransom.Nemty.26C4E7C4
NANO-AntivirusTrojan.Win32.Encoder.gvscqg
MicroWorld-eScanGeneric.Ransom.Nemty.26C4E7C4
TencentWin32.Trojan.Filecoder.Ammv
Ad-AwareGeneric.Ransom.Nemty.26C4E7C4
SophosML/PE-A + Mal/Nemty-Gen
ComodoMalware@#15fkzf2v7fqm2
F-SecureTrojan.TR/Downloader.Gen
BitDefenderThetaAI:Packer.BC568F341E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.NEMTY.SMI
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.7fbd8ffe4b9e0806
EmsisoftGeneric.Ransom.Nemty.26C4E7C4 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Downloader.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2FDFB11
MicrosoftRansom:Win32/Nemty.D
ArcabitGeneric.Ransom.Nemty.26C4E7C4
AegisLabTrojan.Win32.Zenpak.4!c
GDataWin32.Trojan-Ransom.Nemty.A
AhnLab-V3Trojan/Win32.Nemty.R306876
McAfeeRansom-Nemty!7FBD8FFE4B9E
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.Nemty
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.NEMTY.SMI
RisingRansom.Nemty!1.BD61 (CLASSIC)
YandexTrojan.GenAsa!AkR8VLvJicE
IkarusTrojan-Ransom.Nemty
MaxSecureTrojan.Malware.74649578.susgen
FortinetW32/Nemty.A!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml

How to remove Generic.Ransom.Nemty.26C4E7C4?

Generic.Ransom.Nemty.26C4E7C4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment