Worm

Worm:Win32/Neeris removal tips

Malware Removal

The Worm:Win32/Neeris is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Neeris virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Neeris?


File Info:

name: C71B179A577E3275F524.mlw
path: /opt/CAPEv2/storage/binaries/661a1c4d8c6e9ae4aedefd4eb5641ee960d4610226ee73040f9076a69b07d5ed
crc32: 7D38FDE1
md5: c71b179a577e3275f5240ae2c076a805
sha1: a70cac0665f2d7e6b69716d839ed41517f2bd68d
sha256: 661a1c4d8c6e9ae4aedefd4eb5641ee960d4610226ee73040f9076a69b07d5ed
sha512: abb7b1f12f7109d287ca6eea689092e77f5c79fe7bf61a4c5fc02d2a0b7d29a65b30f10ba90c9d27419f081a46aa368575e6546e20dd508f8062c5552ddcbcce
ssdeep: 1536:gGedE/tnbL6jbaYX2TsLr5HVtXHlhn5jN9PuzxNnpTvijbKOEUoCyKG:gGe4nb2yYX2Mr5HvXFRx0xW+UoQG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159838CC0B6B1ED23C0C22777B6258277987BAC2135368D0F898B682BB4B635670FD55D
sha3_384: c3fd97132e27ec6d5746bf3016ff2de3784a7e0269125ed5f0006c84ccc942d44d6973e9ddf8b45289f6e1692d90e950
ep_bytes: 558bec6aff68f060400068a053400064
timestamp: 2009-08-10 00:45:14

Version Info:

0: [No Data]

Worm:Win32/Neeris also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Buzus.kYPv
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeBackDoor-EEF
Cylanceunsafe
ZillyaWorm.Kolab.Win32.840
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0053247e1 )
AlibabaTrojan:Win32/Kryptik.dd01cebb
K7GWTrojan ( 0053247e1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecPacked.Generic.252
ESET-NOD32a variant of Win32/Injector.YQ
APEXMalicious
ClamAVWin.Trojan.Agent-35796
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.429009
NANO-AntivirusTrojan.Win32.Kolab.bxrvd
ViRobotWorm.Win32.Net-Kolab.87040
MicroWorld-eScanGen:Variant.Zusy.429009
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Generic.Sgil
TACHYONWorm/W32.Kolab.87040
EmsisoftGen:Variant.Zusy.429009 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.IRC.Sdbot.11894
VIPREGen:Variant.Zusy.429009
TrendMicroWORM_KOLAB.DT
SophosMal/EncPk-JU
IkarusPacker.Win32.CPEX-based
JiangminWorm/Kolab.to
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLWorm[Net]/Win32.Kolab
MicrosoftWorm:Win32/Neeris
XcitiumTrojWare.Win32.TrojanDownloader.Pher.ABC@1fm75k
ArcabitTrojan.Zusy.D68BD1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.429009
VaristW32/Risk.VRBL-6915
AhnLab-V3Win32/Kolab.worm.Gen
BitDefenderThetaAI:Packer.A0A8BC771F
MAXmalware (ai score=100)
VBA32Net-Worm.Kolab
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Kolabc.AJ.worm
TrendMicro-HouseCallWORM_KOLAB.DT
RisingWorm.Neeris!8.587 (TFE:5:RTD8j4jlvRS)
YandexTrojan.Injector!OXXVkwSw2Ss
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.IA!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.665f2d
DeepInstinctMALICIOUS

How to remove Worm:Win32/Neeris?

Worm:Win32/Neeris removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment