Ransom

Ransom:Win32/Nemty.ARJ!MTB removal

Malware Removal

The Ransom:Win32/Nemty.ARJ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Nemty.ARJ!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to execute a powershell command with suspicious parameter/s
  • A process created a hidden window
  • Unconventionial language used in binary resources: Polish
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Network activity contains more than one unique useragent.
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Clears Windows events or logs
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.ipify.org
nemty11.hk

How to determine Ransom:Win32/Nemty.ARJ!MTB?


File Info:

crc32: 46A2D36F
md5: 0000efd7a890e1e1a93e481288f5bd2a
name: nnn.exe
sha1: b5c5386dcbd850262a7a81ff818343dc306e58ce
sha256: 4799d051f0e40b15ec67593ea838df901613018d26b612d6d2447431323d4a01
sha512: 584b2639ac4e4e2df69b1bee015da7791af9d0089d61d82d937d4a255d81f5ec3d80d04f501a771ecf69f62c8743a7b8616ff3b85be47a5f0e7636ed4b781274
ssdeep: 3072:mnHLnmkpqfHMcPHow/Bw+Zw0jlyNMCCZTImdM1LXjwOYuaF7ZHWAAfne:mnrjpqfsc/H/a+ZRjlc1sMtUuf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersionNew: 2.3.4
InternalServiceName: speedy.exe
Copyright: Copyright (C) 2020, softtail
ProgramVersion: 1.4.7

Ransom:Win32/Nemty.ARJ!MTB also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33380082
McAfeeRansom-Nemty
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 005615631 )
BitDefenderTrojan.GenericKD.33380082
K7GWTrojan ( 005615631 )
Cybereasonmalicious.dcbd85
ArcabitTrojan.Generic.D1FD56F2
TrendMicroRansom.Win32.NEMTY.N
BitDefenderThetaGen:NN.ZexaF.34096.qyW@amxPN5hG
CyrenW32/Trojan.FVTP-5344
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HBMH
TrendMicro-HouseCallRansom.Win32.NEMTY.N
Paloaltogeneric.ml
KasperskyTrojan.Win32.Zenpak.wbd
AlibabaRansom:Win32/Nemty.e3d863f7
NANO-AntivirusTrojan.Win32.Zenpak.hcxhki
RisingTrojan.Kryptik!1.BEC8 (CLOUD)
Ad-AwareTrojan.GenericKD.33380082
EmsisoftTrojan.GenericKD.33380082 (B)
F-SecureTrojan.TR/AD.NemtyRansom.ykamj
DrWebTrojan.MulDrop11.47558
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
SentinelOneDFI – Suspicious PE
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.0000efd7a890e1e1
SophosTroj/Nemty-O
APEXMalicious
JiangminTrojan.Zenpak.bfx
WebrootW32.Ransom.Nemty
AviraTR/AD.NemtyRansom.ykamj
FortinetW32/Kryptik.HBMH!tr
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
MicrosoftRansom:Win32/Nemty.ARJ!MTB
ZoneAlarmTrojan.Win32.Zenpak.wbd
AhnLab-V3Trojan/Win32.MalPe.R327360
Acronissuspicious
VBA32Trojan.MulDrop
ALYacTrojan.Ransom.Nemty
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TencentWin32.Trojan.Agent.Auto
YandexTrojan.Kryptik!uAF/Ez595hs
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_98%
GDataTrojan.GenericKD.33380082
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM10.2.81AB.Malware.Gen

How to remove Ransom:Win32/Nemty.ARJ!MTB?

Ransom:Win32/Nemty.ARJ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment