Ransom

How to remove “Generic.Ransom.Nemty.A5B4C5A6”?

Malware Removal

The Generic.Ransom.Nemty.A5B4C5A6 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Nemty.A5B4C5A6 virus can do?

  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Nemty.A5B4C5A6?


File Info:

crc32: 4061C384
md5: 59cbd230bc08a3087ac1de0a74902222
name: 59CBD230BC08A3087AC1DE0A74902222.mlw
sha1: ecd6d57769be885b900b027e541b02e0c04b62e0
sha256: 9574f57f7a4192f0507fa3361fb3e00e1f1101fdd818fc8e27aaba6714cd373c
sha512: 670f13cb971ecbecc2b254a6dc491ae4ddc3d5449eeb6f3d9fa370b0419a619668171ff00f04a3633cedb5a1bae12fd688a4dc719eba4c2889597ddba988cfcd
ssdeep: 1536:a50hYF6oH6Ygjl7OPKfptRyM1gfcBwYNSkHCh4TxSb8:a506F6MHgtOPKf05fce6VQ4TxSb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Nemty.A5B4C5A6 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005588651 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.29417
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Nemty
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1327491
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Nemty.4f8476f7
K7GWTrojan ( 005588651 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Nemty.A
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Nemty.A5B4C5A6
NANO-AntivirusTrojan.Win32.Filecoder.gcgywj
MicroWorld-eScanDeepScan:Generic.Ransom.Nemty.A5B4C5A6
TencentWin32.Trojan.Filecoder.Sysh
Ad-AwareDeepScan:Generic.Ransom.Nemty.A5B4C5A6
SophosMal/Generic-R + Troj/Nemty-A
ComodoMalware@#3hv0eryob24og
F-SecureTrojan.TR/Downloader.Gen
BitDefenderThetaAI:Packer.FFD0002C1E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.NEMTY.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
FireEyeGeneric.mg.59cbd230bc08a308
EmsisoftDeepScan:Generic.Ransom.Nemty.A5B4C5A6 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ecmyo
AviraTR/Downloader.Gen
Antiy-AVLTrojan[Ransom]/Win32.Nemty
MicrosoftRansom:Win32/Nemty.D
ArcabitDeepScan:Generic.Ransom.Nemty.A5B4C5A6
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.Ransom.Nemty.A5B4C5A6
AhnLab-V3Trojan/Win32.Nemty.R294423
Acronissuspicious
McAfeeRansom-Nemty!59CBD230BC08
MAXmalware (ai score=100)
VBA32BScope.Trojan.Agent
MalwarebytesRansom.Nemty
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.NEMTY.SMTH
RisingRansom.Nemty!1.BD61 (CLOUD)
YandexTrojan.Agent!LBuT1kV6aVY
IkarusTrojan-Ransom.Nemty
FortinetW32/Generic.A!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Nemty.HwoCl58A

How to remove Generic.Ransom.Nemty.A5B4C5A6?

Generic.Ransom.Nemty.A5B4C5A6 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment