Ransom

Ransom:Win32/Nemty.D information

Malware Removal

The Ransom:Win32/Nemty.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Nemty.D virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to execute a powershell command with suspicious parameter/s
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Network activity contains more than one unique useragent.
  • Writes a potential ransom message to disk
  • Contacts C&C server HTTP check-in (Banking Trojan)
  • Attempts to modify proxy settings
  • Clears Windows events or logs
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
www.myexternalip.com
a.tomx.xyz
ocsp.pki.goog
api.db-ip.com
nemty10.hk

How to determine Ransom:Win32/Nemty.D?


File Info:

crc32: E6FBA759
md5: a5d962de3761c8ed95e97d49dcde8f12
name: nem.exe
sha1: c8f960f1747c7325e4cfaaa87a8fc3ed452a0f50
sha256: 5c59f79a1706bbdb2cd0f0d34baea40cee5f15220599c24dca5a535c1c6654a1
sha512: 7048d65a807741a81f8ff155fb7fe01860fba4634e8c7167f38c3c8a2221f8fa19b07432c0f12a2c187a0845fb1029492ebb3a8045b79818c0cba6c4ec8676b6
ssdeep: 1536:RStOoo6j+5UTeLNSTQjn0WLg4xI1kXcteRYVzgQxSOrjpBrO:RKHp+5UiZSqzguRcs4zgQxSOPLrO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Nemty.D also known as:

MicroWorld-eScanGen:Heur.Ransom.Imps.1
McAfeeRansom-Nemty!A5D962DE3761
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Heur.Ransom.Imps.1
K7GWTrojan ( 00556c621 )
K7AntiVirusTrojan ( 00556c621 )
ArcabitTrojan.Ransom.Imps.1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Nemty.A
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Zenpak.vho
AlibabaRansom:Win32/Genasom.ali1000102
NANO-AntivirusTrojan.Win32.Encoder.gxsssr
RisingRansom.Nemty!1.BD61 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftGen:Heur.Ransom.Imps.1 (B)
F-SecureTrojan.TR/Downloader.Gen
DrWebTrojan.Encoder.30832
ZillyaTrojan.Filecoder.Win32.12172
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Rimecud.nh
FortinetW32/Filecoder_Nemty.A!tr
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.a5d962de3761c8ed
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
JiangminTrojan.Zenpak.axc
WebrootW32.Malware.Gen
AviraTR/Downloader.Gen
MAXmalware (ai score=84)
MicrosoftRansom:Win32/Nemty.D
ZoneAlarmHEUR:Trojan.Win32.Zenpak.vho
AhnLab-V3Trojan/Win32.Nemty.C3974898
Acronissuspicious
VBA32BScope.Trojan.Encoder
ALYacGen:Heur.Ransom.Imps.1
Ad-AwareGen:Heur.Ransom.Imps.1
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Nemty.R015C0DB820
TencentWin32.Trojan.Filecoder.Loht
GDataGen:Heur.Ransom.Imps.1
BitDefenderThetaAI:Packer.8D8C4BDE1E
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.e3761c
AvastWin32:RansomX-gen [Ransom]
MaxSecureTrojan.Malware.74773626.susgen

How to remove Ransom:Win32/Nemty.D?

Ransom:Win32/Nemty.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment