Trojan

Trojan:Win32/Nedsym.G removal tips

Malware Removal

The Trojan:Win32/Nedsym.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Nedsym.G virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Kyrgyz
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
wrici.ru
wsene.ru

How to determine Trojan:Win32/Nedsym.G?


File Info:

crc32: C69D550C
md5: 0720297c830ba6c63330b5b80cbe87de
name: 0720297C830BA6C63330B5B80CBE87DE.mlw
sha1: 194dd208e8de28183b3cbe0c502328e1a721ca7f
sha256: 8a70371eaa1ec6dab9efa81b9d2672615327d6c040760b69e01a9ec13a5fc8b1
sha512: a32a6101737d7e7b76a4593a34512f5cb8635cb95be44334a4400e4df1d9cf01b37936a836554a9f0f91278e35be1e3c916f8c3850ccd96d6725a0ab4f70154b
ssdeep: 3072:U5pVDGhHnDo1Ke+ZLQuuCdEoAInQ7HYb9ifmlpF:CJGZne+LQujdmp7GEu
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

Translation: 0x0409 0x04b0
InternalName: Djgt4HpKLz
FileVersion: 8.851.0014
CompanyName: OI
ProductName: N1JegK
ProductVersion: 8.851.0014
OriginalFilename: Djgt4HpKLz.exe

Trojan:Win32/Nedsym.G also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Barys.78630
FireEyeGeneric.mg.0720297c830ba6c6
McAfeeArtemis!0720297C830B
CylanceUnsafe
VIPRELooksLike.Win32.Malware!vb (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce71 )
BitDefenderGen:Variant.Barys.78630
K7GWTrojan ( 004bcce71 )
Cybereasonmalicious.c830ba
CyrenW32/VBcrypt.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:GenMalicious-LVX [Trj]
ClamAVWin.Trojan.Agent-368466
KasperskyTrojan-Ransom.Win32.Blocker.hejm
AlibabaRansom:Win32/Blocker.6f1416bf
NANO-AntivirusTrojan.Win32.Jorik.jsxtq
AegisLabTrojan.Win32.Blocker.4!c
Ad-AwareGen:Variant.Barys.78630
SophosMal/Generic-S
ComodoSuspicious@#3a8s7lm7gu1ls
F-SecureTrojan.TR/Crypt.PEPM.Gen
ZillyaTrojan.Jorik.Win32.7119
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
EmsisoftGen:Variant.Barys.78630 (B)
JiangminTrojan.Blocker.rcn
eGambitUnsafe.AI_Score_96%
AviraTR/Crypt.PEPM.Gen
Antiy-AVLTrojan[Backdoor]/Win32.DMSpammer
KingsoftWin32.Troj.Jorik.dw.(kcloud)
MicrosoftTrojan:Win32/Nedsym.G
ArcabitTrojan.Barys.D13326
SUPERAntiSpywareTrojan.Agent/Gen-FraudPacked
ZoneAlarmTrojan-Ransom.Win32.Blocker.hejm
GDataGen:Variant.Barys.78630
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.VBKrypt.C15879
BitDefenderThetaAI:Packer.BC62FD8F20
ALYacGen:Variant.Barys.78630
MAXmalware (ai score=100)
VBA32Malware-Cryptor.VB.gen.1
MalwarebytesMalware.Heuristic.1001
PandaTrj/Spyeyes.J
ESET-NOD32a variant of Win32/Injector.GQR
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Injector!h5WSqlZMACo
IkarusTrojan-PWS.SuspectCRC
FortinetW32/VBInjector.W!tr
WebrootW32.Pdf.Exploit
AVGWin32:GenMalicious-LVX [Trj]
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Ransom.Blocker.HgIASPkA

How to remove Trojan:Win32/Nedsym.G?

Trojan:Win32/Nedsym.G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment