Malware

Nemesis.8885 removal tips

Malware Removal

The Nemesis.8885 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Nemesis.8885 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location

How to determine Nemesis.8885?


File Info:

name: 24DB94A315BDDDC9EF03.mlw
path: /opt/CAPEv2/storage/binaries/b303ce1f96d34a81790ac83906a5861b8650fbbb5fede58dd58384eb27f676ad
crc32: 62CDC661
md5: 24db94a315bdddc9ef0382b139d896c6
sha1: ad8f800e5f2ce919882bd1c8b37e38bac8bf5737
sha256: b303ce1f96d34a81790ac83906a5861b8650fbbb5fede58dd58384eb27f676ad
sha512: 246a57f73540e54facbb20355ec22462f9baa9ecb826b12bd24a3ea7648ca89625f55fc1e813d210c3bb0c3d8c0d95ce098d5da9160f9726e6d5cfc9ddaed4b4
ssdeep: 12288:732Ls4yuocuAtcMAKsj92oJ6tOYpOP4Y9W4n8ZlXvAGI6GT3tM48GIF6c:732MKptAKEJZnQlfAGI6o8qc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165F412206270C8A3D4875431DC2BBEF167A7BE16C430876717A3BDAFF9F6289491918D
sha3_384: 1225ab0d9fb61243a350b8cc541a433de65c1510b103be8ac5428227aa1c496fc370d32a21fcc368eed6f1453c69b7fd
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:53:44

Version Info:

Comments: Rnnebo Synkrocyklotroners141
CompanyName: Kevyn Tandpiner tandhjulets Adoptivdtre
FileVersion: 1.22.21
ProductName: Inaudibleness Admonitory
Translation: 0x0409 0x04b0

Nemesis.8885 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Nemesis.8885
FireEyeGen:Variant.Nemesis.8885
ALYacGen:Variant.Nemesis.8885
K7AntiVirusTrojan ( 005955231 )
K7GWTrojan ( 005955231 )
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32NSIS/Injector.AZW
ClamAVWin.Dropper.Nanocore-9947074-0
KasperskyHEUR:Trojan-Downloader.Win32.GuLoader.gen
BitDefenderGen:Variant.Nemesis.8885
NANO-AntivirusTrojan.Win32.GuLoader.jpxlpb
AvastNSIS:InjectorX-gen [Trj]
EmsisoftGen:Variant.Nemesis.8885 (B)
VIPREGen:Variant.Nemesis.8885
McAfee-GW-EditionArtemis
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
JiangminTrojan.Fsysna.niv
AviraTR/Injector.sgezk
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan-Downloader.Dunilaber.7VBHQ5
CynetMalicious (score: 100)
McAfeeArtemis!24DB94A315BD
MAXmalware (ai score=80)
FortinetNSIS/Injector.AOW!tr
AVGNSIS:InjectorX-gen [Trj]

How to remove Nemesis.8885?

Nemesis.8885 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment