Malware

Nemesis.23220 information

Malware Removal

The Nemesis.23220 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Nemesis.23220 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Suspicious wmic.exe use was detected
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Nemesis.23220?


File Info:

name: 450DA33EE1773E6941F4.mlw
path: /opt/CAPEv2/storage/binaries/4862f4ab81583882216b5380d853277b863734c45d55eed1549a7ce5755a7dc0
crc32: 1F50524D
md5: 450da33ee1773e6941f4201d55f434ae
sha1: 0f9579698eb74213cc42be46beb56a1aedc833f3
sha256: 4862f4ab81583882216b5380d853277b863734c45d55eed1549a7ce5755a7dc0
sha512: dc46bcfce0df527dd790d263abc6eb50179b419d10677da143309dadd1bd10890202b65172d8518772c541b7168ddc5293020b1e29c9f1712d24d1646ee2e985
ssdeep: 24576:gz4ABZyzsZASbxl0SXW+eYrKPrm/6Jbirrt7p44j0va:VmQzsZxbfnXVSvOt7bjua
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D15235B32D8E4E3D6036133CD73C6A591E9733842621B67FB817D77A88432F6678816
sha3_384: 25eb83931a9a9cef6316b3d50da7f54a3e9cb30c3eae8a2fe1244f64ad645eabf0b91c21277bdeeb0df42d15c84c3331
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

Nemesis.23220 also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.Generic.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Nemesis.23220
FireEyeGen:Variant.Nemesis.23220
SkyhighRDN/Generic Downloader.x
McAfeeArtemis!450DA33EE177
Cylanceunsafe
ZillyaAdware.GenericCRTD.Win32.1396
SangforPUA.Win32.Sign.a
AlibabaAdWare:Win32/Adload.67640cda
K7GWTrojan-Downloader ( 004dea141 )
K7AntiVirusTrojan-Downloader ( 004dea141 )
SymantecSMG.Heur!gen
ESET-NOD32MSIL/TrojanDownloader.Adload.AX
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Nemesis.23220
NANO-AntivirusTrojan.Win32.Zadved.dytyep
SUPERAntiSpywarePUP.Somoto/Variant
AvastWin32:Adware-gen [Adw]
TencentWin32.Trojan.FalseSign.Cnhl
EmsisoftAdware.Generic (A)
F-SecureHeuristic.HEUR/AGEN.1333059
DrWebTrojan.DownLoader21.43120
VIPREGen:Variant.Nemesis.23220
Trapminesuspicious.low.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusTrojan-Downloader.MSIL.Adload
AviraHEUR/AGEN.1333059
Antiy-AVLTrojan[Downloader]/MSIL.AdLoad
Kingsoftmalware.kb.a.895
MicrosoftPUADlManager:Win32/OpenDownloadManager
ArcabitTrojan.Nemesis.D5AB4
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
GDataGen:Variant.Nemesis.23220
CynetMalicious (score: 99)
ALYacGen:Variant.Nemesis.23220
MAXmalware (ai score=80)
VBA32Downloader.Agent
MalwarebytesAdload.Adware.Downloader.DDS
PandaTrj/CI.A
RisingDownloader.Adload!8.D1 (CLOUD)
YandexTrojan.DL.Adload!QzVfUcuW6ng
SentinelOneStatic AI – Suspicious PE
MaxSecureDownloader.W32.Agent.gen_262059
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS

How to remove Nemesis.23220?

Nemesis.23220 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment