Malware

How to remove “Win32/Neurevt.B”?

Malware Removal

The Win32/Neurevt.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Neurevt.B virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Galician
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VMware through the presence of a registry key
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Neurevt.B?


File Info:

name: BB59AB913962DB26F9F6.mlw
path: /opt/CAPEv2/storage/binaries/ddaae6ac859eb21a6329b04f7c8d0286196072ffecce9514119919df31ccde89
crc32: A44B0005
md5: bb59ab913962db26f9f65da0de3b8d31
sha1: 3dde67a5626070edf13d2a689f9ffb2bd0b4d137
sha256: ddaae6ac859eb21a6329b04f7c8d0286196072ffecce9514119919df31ccde89
sha512: 1d21663959d87854325f8667e963765986663dbb5e1390ccc03e22228371f8d23cdf37d2b1240413f2e0eaf2d656662cabeb6b8eaeda97c7bdf01704df21c889
ssdeep: 3072:7gELRGXYxSPtCw76PJ5uJKyQZBvPTJsP6NbhLpsdKwL4rR37nA:7bcJRioJ0f7JpblSdKw4Rn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159D312B618364F59FB382DF1F4E64ADEA57C0A4B1FDBC090574E73FB59801880AB851A
sha3_384: 9c026b5502229e1309272988372be6e7b0f93a33b019d9010103ca7b811e1bd3dd302e7e6ed2232e1b24c8a833194a8b
ep_bytes: 558bec5164a130000000535685c07406
timestamp: 2014-01-10 00:46:30

Version Info:

0: [No Data]

Win32/Neurevt.B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Neurevt.tpcK
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.bb59ab913962db26
CAT-QuickHealTrojan.MauvaiseRI.S5249005
SkyhighBehavesLike.Win32.PdfCrypt.cc
McAfeePWS-FABN!BB59AB913962
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Tdss.27
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Neurevt.d1cd73ff
K7GWTrojan ( 0048bd571 )
K7AntiVirusTrojan ( 0048bd571 )
BaiduWin32.Trojan.Neurevt.d
VirITTrojan.Win32.Betabot.D
SymantecTrojan.Betabot!gm
tehtrisGeneric.Malware
ESET-NOD32Win32/Neurevt.B
APEXMalicious
ClamAVWin.Malware.Neurevt-6987362-1
KasperskyTrojan.Win32.Neurevt.anc
BitDefenderGen:Variant.Tdss.27
NANO-AntivirusTrojan.Win32.Pincav.cqslmo
MicroWorld-eScanGen:Variant.Tdss.27
AvastWin32:Neurevt-J [Cryp]
TACHYONTrojan/W32.Pincav.141312.D
EmsisoftGen:Variant.Tdss.27 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebTrojan.Betabot.3
ZillyaTrojan.Neurevt.Win32.1538
TrendMicroBKDR_NEUREVT.SMC
Trapminemalicious.high.ml.score
SophosMal/Neurevt-A
IkarusTrojan.Win32.Neurevt
GDataGen:Variant.Tdss.27
JiangminTrojan/Neurevt.sf
WebrootW32.Malware.gen
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan/Win32.Scar
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Neurevt.B@56lmsx
ArcabitTrojan.Tdss.27
ViRobotTrojan.Win32.Agent.142336.N
ZoneAlarmTrojan.Win32.Neurevt.anc
MicrosoftTrojan:Win32/Neurevt.A
VaristW32/Trojan.DMBR-8218
AhnLab-V3Trojan/Win32.Scar.C199542
BitDefenderThetaAI:Packer.FEDDA2851F
ALYacGen:Variant.Tdss.27
MAXmalware (ai score=100)
VBA32BScope.Trojan.Betabot
Cylanceunsafe
PandaTrj/Dtcontx.I
TrendMicro-HouseCallBKDR_NEUREVT.SMC
RisingTrojan.Neurevt!8.B7F (TFE:2:KChORLv2F8E)
YandexTrojan.GenAsa!sZBB3Q6z+Ms
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7385769.susgen
FortinetW32/Neurevt.BN!tr
AVGWin32:Neurevt-J [Cryp]
DeepInstinctMALICIOUS

How to remove Win32/Neurevt.B?

Win32/Neurevt.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment