Ransom

About “Ransom:Win32/Nemty.PH!MTB” infection

Malware Removal

The Ransom:Win32/Nemty.PH!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Nemty.PH!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Japanese
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
gatsby.best

How to determine Ransom:Win32/Nemty.PH!MTB?


File Info:

crc32: FBBCE402
md5: 0ad5c8a63690edd5a1637d0b3313c78c
name: 0AD5C8A63690EDD5A1637D0B3313C78C.mlw
sha1: dbd0e52f090cbb7561c89e36ebbbcd1c48d3f980
sha256: 9a01130d0eb78b2512307dcd73deaf7582a6af4eac1f16d1ecc0e38f3c1cfbc6
sha512: e96dc1517250a5acb6128cde6f2d63348db9e667319aa57c943a3501fe5f050b14e4e70a0938637f3c1ed09de3b28eb328fdadf646b05d1cdb87696ff09de5e3
ssdeep: 6144:2s/PHbZhgIuMvPHj0gMe/rkrCq5UxCYS3klLAJypI:vnHbbggHHj044rzdYZls2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019, fdbb
InternalName: sfsgvsdg.exe
FileVersion: 1.3.4
ProductVersion: 1.3.6

Ransom:Win32/Nemty.PH!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AzorultRI.S10666641
ALYacTrojan.GenericKD.32911514
CylanceUnsafe
ZillyaTrojan.Azorult.Win32.1
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Azorult.50274356
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.63690e
CyrenW32/Trojan.XYAM-9202
SymantecRansom.Nemty
ESET-NOD32Win32/PSW.Delf.OSF
ZonerTrojan.Win32.88485
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Dropper.Tofsee-9815999-0
KasperskyTrojan-PSW.Win32.Azorult.aipb
BitDefenderTrojan.GenericKD.32911514
NANO-AntivirusTrojan.Win32.Delf.hchekg
MicroWorld-eScanTrojan.GenericKD.32911514
TencentWin32.Trojan-qqpass.Qqrob.Isr
Ad-AwareTrojan.GenericKD.32911514
SophosMal/Generic-S + Mal/GandCrab-G
BitDefenderThetaGen:NN.ZexaF.34688.pq0@aCcuCkcG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.NEMTY.ELDC
McAfee-GW-EditionBehavesLike.Win32.Emotet.dh
FireEyeGeneric.mg.0ad5c8a63690edd5
EmsisoftTrojan.GenericKD.32911514 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.PSW.Azorult.gok
WebrootTrojan.Dropper.Gen
AviraTR/AD.MoksSteal.ybjyr
Antiy-AVLTrojan/Generic.ASMalwS.303DD3B
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Nemty.PH!MTB
AegisLabTrojan.Multi.Generic.4!c
GDataWin32.Trojan-Stealer.Azorult.GA22R0
AhnLab-V3Trojan/Win32.MalPe.R307385
McAfeeArtemis!0AD5C8A63690
MAXmalware (ai score=87)
VBA32Trojan.Wacatac
MalwarebytesSpyware.PasswordStealer
PandaTrj/WLT.F
TrendMicro-HouseCallRansom.Win32.NEMTY.ELDC
RisingTrojan.Kryptik!1.C0F7 (KTSE)
YandexTrojan.GenAsa!91l+u0kfu3I
IkarusTrojan.SuspectCRC
FortinetW32/Azorult.AIPB!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Ransom:Win32/Nemty.PH!MTB?

Ransom:Win32/Nemty.PH!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment