Malware

About “Win32/Nevereg.A” infection

Malware Removal

The Win32/Nevereg.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Nevereg.A virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Win32/Nevereg.A?


File Info:

name: AF2AB6FE624EF5D51250.mlw
path: /opt/CAPEv2/storage/binaries/e4cd2bc081addc1059dc57a03fc8bb9ac0954177faf028b4b7cd29fa2c6a106d
crc32: E3CF0E22
md5: af2ab6fe624ef5d51250636ea5aa5f69
sha1: 625c3e9753fca6dabe05c4c6df0d41bd85a2513b
sha256: e4cd2bc081addc1059dc57a03fc8bb9ac0954177faf028b4b7cd29fa2c6a106d
sha512: 0d1774bfce44a52256c2f5caef7b6681f772608b6aa961e3e66dc0aa2828af60bcb62ff73e1856ee22406e54db23d9e308d1ea508eb056d719e8c94ff69777a1
ssdeep: 768:9GvbqsQdX5BhGEnOsIzfJ4i4g5p0syi+hvN18K3H8T6++3Kd8VVrGaJat:4zqsQ5PIt4+/yfeB6rXVrGaQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12F336C97F2D3D93ED2210AFD5C068248E92FB6223D6628D17EF90F0C4A6F3845D2D599
sha3_384: f71290c1500939ac56c08ac931b2426b62ee29bdf10c0b49be35006a10ab37607dd1326abac2548a8ddef9f4c3a8de83
ep_bytes: 558bec83c4f0b8b0a54000e8c49effff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Nevereg.A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Pluton.46080
MicroWorld-eScanDeepScan:Generic.Malware.PfV!hid!!p2p!u.5BD3485A
CAT-QuickHealTrojan.GenericIH.S22398512
ALYacDeepScan:Generic.Malware.PfV!hid!!p2p!u.5BD3485A
CylanceUnsafe
ZillyaWorm.Nevereg.Win32.1
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e624ef
BitDefenderThetaAI:Packer.39B1114021
CyrenW32/Nevereg.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Nevereg.A
TrendMicro-HouseCallWORM_NEVEREG.A
KasperskyEmail-Worm.Win32.Nevereg
BitDefenderDeepScan:Generic.Malware.PfV!hid!!p2p!u.5BD3485A
NANO-AntivirusTrojan.Win32.Nevereg.enis
AvastWin32:Malware-gen
RisingWorm.Mail.Nevereg (CLASSIC)
Ad-AwareDeepScan:Generic.Malware.PfV!hid!!p2p!u.5BD3485A
SophosML/PE-A + W32/Nevereg-A
VIPREBehavesLike.Win32.Malware.tsc (mx-v)
TrendMicroWORM_NEVEREG.A
McAfee-GW-EditionBehavesLike.Win32.Eggnog.ph
FireEyeGeneric.mg.af2ab6fe624ef5d5
EmsisoftDeepScan:Generic.Malware.PfV!hid!!p2p!u.5BD3485A (B)
IkarusEmail-Worm.Win32.Fearso
GDataWin32.Trojan.PSE.1DSGD0B
JiangminWorm.Nevereg.a
AviraWORM/Nevereg.A.1
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.4C07C
ArcabitDeepScan:Generic.Malware.PfV!hid!!p2p!u.5BD3485A
MicrosoftWorm:Win32/Nevereg.A@mm
CynetMalicious (score: 100)
AhnLab-V3Worm/Win.Generic.R449555
Acronissuspicious
McAfeeGenericRXAA-AA!AF2AB6FE624E
VBA32Worm.Nevereg
MalwarebytesMalware.AI.1690996891
APEXMalicious
TencentTrojan.Win32.BitCoinMiner.la
YandexI-Worm.Nevereg!G6bebm/WEdY
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Nevereg.A!worm
AVGWin32:Malware-gen
PandaWorm Generic.LC
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Nevereg.A?

Win32/Nevereg.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment