Malware

What is “Nemesis.1695”?

Malware Removal

The Nemesis.1695 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Nemesis.1695 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Nemesis.1695?


File Info:

name: 326F1550D489A00E9177.mlw
path: /opt/CAPEv2/storage/binaries/833418175812807d0662a4ce99cd47346ec2b038c13c3f9fca99991276bea993
crc32: 306F8EF2
md5: 326f1550d489a00e9177f12f98245dab
sha1: 12b4334165bb3bb84599e7fbaac2a1fb681d4169
sha256: 833418175812807d0662a4ce99cd47346ec2b038c13c3f9fca99991276bea993
sha512: 2aa6e2139a322d1ab3e1cc4e7417e018eb8ac67e5a60edf3674d83bf296256ebe7f70a92e722fa80ce4c60a20574a18cdd3731e9fad91e91341af377ee7de6c0
ssdeep: 98304:BPgciNjFacXFl5EGVZoSPOpD5gBXwiGm9iM3pcYjTdN5o:BYJPevi/oM3OQf5o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AD2633F0CDCAC061D469797261B44A5C78B297B040BAEB1D424DDFFA32CEBD11E7852A
sha3_384: f52ecbf462b0ea0f2edbdcdb49610a626aaa83113b685beb579275afc9a3ca0c035ec043cec3257a7ef36d618a326c9d
ep_bytes: 81ecd4020000535556576a2033ed5e89
timestamp: 2012-02-24 19:19:59

Version Info:

Comments: Copyright (c) 2014
FileDescription: For Windows
FileVersion: 1.186.0.0
LegalCopyright: Copyright (c) 2014
Translation: 0x0000 0x04b0

Nemesis.1695 also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Nemesis.1695
FireEyeGen:Variant.Nemesis.1695
ALYacGen:Variant.Zusy.335556
CylanceUnsafe
VIPREGen:Variant.Nemesis.1695
SangforAdware.Win32.Agent.gen
AlibabaAdWare:Win32/AddLyrics.2ba0f316
Cybereasonmalicious.0d489a
ArcabitTrojan.Nemesis.D69F
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.NSIS.Agent.gen
BitDefenderGen:Variant.Nemesis.1695
NANO-AntivirusTrojan.Win32.Revizer.dmtrsm
AvastWin32:Dropper-gen [Drp]
TencentNsis.Adware.Agent.Lhxf
EmsisoftGen:Variant.Nemesis.1695 (B)
ComodoApplication.Win32.AddLyrics.ANGL@5qi050
DrWebTrojan.Revizer.394
ZillyaAdware.Agent.Win32.173933
McAfee-GW-EditionBehavesLike.Win32.PUP.rc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
WebrootPua.Addlyrics
GoogleDetected
AviraHEUR/AGEN.1207392
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.3C54
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftPUAAdvertising:Win32/Lyrics
GDataNSIS.Adware.AddLyrics.I
CynetMalicious (score: 99)
AhnLab-V3Adware/Win32.AddLyrics.R133211
McAfeeArtemis!326F1550D489
VBA32BScope.Adware.AddLyrics
MalwarebytesAdware.AdLyrics
TrendMicro-HouseCallTROJ_GEN.R002H0CGS22
RisingTrojan.Occamy!8.F1CD (TFE:5:BxPysKj22CB)
YandexPUA.AddLyrics!8T6xOpMa0EQ
IkarusAdWare.AddLyrics
AVGWin32:Dropper-gen [Drp]
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Nemesis.1695?

Nemesis.1695 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment