Ransom

About “Ransom:Win32/Nemreq.A” infection

Malware Removal

The Ransom:Win32/Nemreq.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Nemreq.A virus can do?

  • Reads data out of its own binary image
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
avtomoika234.cc

How to determine Ransom:Win32/Nemreq.A?


File Info:

crc32: 9B65D610
md5: 9a9fed716fe22ed6107cfb7a9b3effd0
name: 9A9FED716FE22ED6107CFB7A9B3EFFD0.mlw
sha1: 5296ee253f40e06d43ba5fb1071a2531a0d5d7d3
sha256: 53d83c54092ffd96113757db138210c7811d10ff53ba38ebee33a331c5191038
sha512: 85c0f4ad424717dab682370a3e37dd5eaa68fc36373ea91f99e06e4bde16db60305a5c1888f053630bc87ffd9b2cbd1be7358450c33c3e3ce42f6860a030e5d8
ssdeep: 12288:MJOxKEy+ffKerjFtoiLMJ2qsMEieZhSM7FQ8I0:MgKEy+jTv5Bf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: All rights reserved
FileDescription: FileBack PC Installation
FileVersion: 4.1.090415
Comments: This installation was built with InstallAware: http://www.installaware.com
CompanyName: Maximum Output Software
Translation: 0x0409 0x04e4

Ransom:Win32/Nemreq.A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
FireEyeGeneric.mg.9a9fed716fe22ed6
McAfeeArtemis!9A9FED716FE2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Generic.5
K7AntiVirusTrojan ( 004f295d1 )
BitDefenderGen:Heur.Ransom.REntS.Gen.1
K7GWTrojan ( 004f295d1 )
SymantecRansom.TeslaCrypt
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Genasom.ali1000102
NANO-AntivirusTrojan.Win32.Encoder.epinru
RisingRansom.Nemreq!8.7B34 (CLOUD)
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
EmsisoftTrojan-Ransom.Crysis (A)
ComodoMalware@#2oz6tq2xwos8d
F-SecureTrojan.TR/AD.RansomHeur.nhcds
DrWebTrojan.Encoder.4118
ZillyaTrojan.Filecoder.Win32.4631
TrendMicroRansom_CRYSIS.F117DC
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
SophosMal/Generic-S
IkarusTrojan.Win32.Filecoder
AviraTR/AD.RansomHeur.nhcds
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Nemreq.A
ArcabitTrojan.Ransom.REntS.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Ransom.REntS.Gen.1
CynetMalicious (score: 100)
Acronissuspicious
VBA32suspected of Trojan.Notifier.gen
ALYacGen:Heur.Ransom.REntS.Gen.1
MAXmalware (ai score=100)
MalwarebytesMalware.AI.4037246187
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Filecoder.Crysis.B
TrendMicro-HouseCallRansom_CRYSIS.F117DC
TencentTrojan.Win32.Nemreq.a
YandexTrojan.GenAsa!RrzQPDexpRM
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/Generic.AC.3EE5C5!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HgIASOgA

How to remove Ransom:Win32/Nemreq.A?

Ransom:Win32/Nemreq.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment