Malware

About “Nemesis.22779” infection

Malware Removal

The Nemesis.22779 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Nemesis.22779 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Nemesis.22779?


File Info:

name: 38BE27FFA565FBA3377D.mlw
path: /opt/CAPEv2/storage/binaries/48676b955c3e4657e77b5e4e20a591f92c6cc9c5214b9fff07311f36ec9aee81
crc32: 85486BB3
md5: 38be27ffa565fba3377d5cf2c642dccc
sha1: a93b814703e0c8d94bac5b16a1b4f81a9c2383a7
sha256: 48676b955c3e4657e77b5e4e20a591f92c6cc9c5214b9fff07311f36ec9aee81
sha512: 40cb03df83171c99dcb5ef2f9cda22dea65f25d247c9f3efee44c19ae3fdcd53a6c837f8e73f154d6e06d23bca6d7d872c274291f91701e2646f8a31b2836edf
ssdeep: 6144:PYa60LkkbRMxWJpqwFpSXV6jCV4LnOaCIF50CHvkDA:PY6L1iWTqiSMj88n4IFKCHwA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T186441324B388E457E8A34B30267BD717EED7913740B4ED0A63A02E287964791DE1F723
sha3_384: 57e72e737d8c6ad96fc4a3cb3e8100e1293a01cbd26fad08b8eb2c396c3277884b605d14fa50f5f6bf881b920eb68768
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:56:47

Version Info:

CompanyName: herbariia
FileDescription: Chapland
FileVersion: 36.36.11.36
LegalCopyright: Copyright curelessly
ProductName: 36.36.11.36
Translation: 0x0409 0x04b0

Nemesis.22779 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.tshg
MicroWorld-eScanGen:Variant.Nemesis.22779
FireEyeGeneric.mg.38be27ffa565fba3
McAfeeArtemis!38BE27FFA565
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005a8a8d1 )
AlibabaTrojan:Win32/Injector.2d8df820
K7GWTrojan ( 005a7f491 )
Cybereasonmalicious.703e0c
VirITTrojan.Win32.Genus.RSQ
CyrenW32/Ninjector.JO.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ETCB
ZonerTrojan.Win32.158408
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Loader.gen
BitDefenderGen:Variant.Nemesis.22779
AvastWin32:InjectorX-gen [Trj]
TencentWin32.Trojan.Strab.Cnhl
EmsisoftGen:Variant.Nemesis.22779 (B)
F-SecureTrojan.TR/Injector.ajnru
VIPREGen:Variant.Nemesis.22779
TrendMicroTROJ_GEN.R002C0PG423
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.NSISX.Spy.Gen.24
AviraTR/AD.Swotter.rbpla
ArcabitTrojan.Nemesis.D58FB [many]
ZoneAlarmHEUR:Trojan-Spy.Win32.Noon.gen
MicrosoftTrojan:Win32/Formbook.RG!MTB
GoogleDetected
AhnLab-V3Trojan/Win.NSISInject.R587856
Acronissuspicious
VBA32Trojan.Dllinject
ALYacGen:Variant.Tedy.391406
MAXmalware (ai score=85)
MalwarebytesTrojan.Loader
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PG423
RisingTrojan.Injector!8.C4 (TFE:5:LXw3ZDM1DxB)
IkarusTrojan-Spy.FormBook
FortinetNSIS/Agent.DCAC!tr
AVGWin32:InjectorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Nemesis.22779?

Nemesis.22779 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment