Malware

How to remove “Nemesis.26959”?

Malware Removal

The Nemesis.26959 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Nemesis.26959 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Nemesis.26959?


File Info:

name: 33F97FABB9B81E3275DE.mlw
path: /opt/CAPEv2/storage/binaries/c637eed78c31104ac279ddc83cfcf7fb2b0a6e112200ae64b2e2576e996c618f
crc32: 1CCF0A60
md5: 33f97fabb9b81e3275de3f9a7ca8851d
sha1: a64e7f16cede76ed4fd6218288eaface4d14c5ee
sha256: c637eed78c31104ac279ddc83cfcf7fb2b0a6e112200ae64b2e2576e996c618f
sha512: 7c95fcda39d3691eb6b65f530d297eeea3b914cf95f2b10910f89dd364d6320af8feee129c172012beeb7a581a28b296f40482476b2a5c82c067b8c6a667cf3d
ssdeep: 3072:+w4gnScGuDI2dcbGRJinqiq/9Gm0UPeMWHkvyPh+XTuZ:+z2heqiq11l1vBW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142C326136AECBCEEC4716670377BE7E5D36EED180121C94E66C41A26E87D053BA023C9
sha3_384: 8b766a861cd9584d608f0e7038ab6e373026c1a877ac7420cd7d7125de82a27b188c941cb52896172b13c824087e557c
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-07-25 00:55:54

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft DirectX Diagnostic Tool
FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
InternalName: dxdiag.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dxdiag.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.16299.15
Translation: 0x0409 0x04b0

Nemesis.26959 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
AVGWin32:Evo-gen [Trj]
MicroWorld-eScanTrojan.NSISX.Spy.Gen.4
FireEyeGen:Variant.Nemesis.26959
ALYacTrojan.NSISX.Spy.Gen.4
MalwarebytesGeneric.Injector.Malicious.DDS
SangforSpyware.Win32.Injector.Vpjl
K7AntiVirusTrojan ( 005420d21 )
AlibabaTrojan:Win32/Injector.6849d41c
K7GWTrojan ( 005420d21 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32NSIS/Injector.AEC
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Nemesis.26959
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Nemesis.26959 (B)
VIPRETrojan.NSISX.Spy.Gen.4
TrendMicroTROJ_GEN.R002C0PHD23
McAfee-GW-EditionRDN/Generic PWS.y
SophosMal/Generic-S
GDataTrojan.NSISX.Spy.Gen.4
WebrootW32.Malware.Gen
MAXmalware (ai score=87)
ArcabitTrojan.NSISX.Spy.Gen.4
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win32.RL_Generic.R349669
McAfeeRDN/Generic PWS.y
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PHD23
RisingTrojan.Injector/NSIS!1.BFBB (CLASSIC)
FortinetW32/Injector.AFV!tr
DeepInstinctMALICIOUS

How to remove Nemesis.26959?

Nemesis.26959 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment