Worm

About “Worm:Win32/NeksMiner.A” infection

Malware Removal

The Worm:Win32/NeksMiner.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/NeksMiner.A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Appears to use command line obfuscation
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities
  • Uses XCOPY for copying files

How to determine Worm:Win32/NeksMiner.A?


File Info:

name: 938150F91D742C07236F.mlw
path: /opt/CAPEv2/storage/binaries/43a76564e07435ac07f3d3d3ab49885bd0bf8562d0c14a87fc2d536d4c94b62b
crc32: 7F96B570
md5: 938150f91d742c07236f8bf8c4823028
sha1: 9a375e941eb880f0f8be3d8cef2e149b74df140b
sha256: 43a76564e07435ac07f3d3d3ab49885bd0bf8562d0c14a87fc2d536d4c94b62b
sha512: 12ad34b4acbe9499e789790f6b7809846f873b148d84dae895f3989901ee2fba2af9734f47670144fb5a16067ca54e44e5f01fc49804b02dc0cb4ceb510e9c2d
ssdeep: 24576:YavAavAavAavAavAavAavAavAavAavAavAavAavAav:YeAeAeAeAeAeAeAeAeAeAeAeAeAe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16665CF9672E0C1A7E093463195AFDBB6EBB3B811321541133B603FAF3D35283642A757
sha3_384: 145b627afa81a443a988c89301a1ac8c794c346dc46a6049f6fef49bdfb783e22df751a4312426c4a674c3872a7c2285
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:52:01

Version Info:

0: [No Data]

Worm:Win32/NeksMiner.A also known as:

LionicWorm.NSIS.BitMin.o!c
Elasticmalicious (high confidence)
DrWebTrojan.BtcMine.2062
MicroWorld-eScanDeepScan:Generic.BitcoinMiner.9.863E68DE
CAT-QuickHealTrojan.NSIS.Miner.ZZ
ALYacDeepScan:Generic.BitcoinMiner.9.863E68DE
CylanceUnsafe
K7AntiVirusTrojan ( 004da88f1 )
AlibabaWorm:Win32/BitMin.7b8b212b
K7GWTrojan ( 004da88f1 )
Cybereasonmalicious.91d742
SymantecTrojan.Coinbitminer
ESET-NOD32NSIS/CoinMiner.T
TrendMicro-HouseCallCoinminer.Win32.MALXMR.AOODAN
Paloaltogeneric.ml
KasperskyWorm.NSIS.BitMin.d
BitDefenderDeepScan:Generic.BitcoinMiner.9.863E68DE
NANO-AntivirusTrojan.Nsis.Agent.echzfj
AvastWin32:Mykings-U [Trj]
TencentNsis.Worm.Bitmin.Hsrx
Ad-AwareDeepScan:Generic.BitcoinMiner.9.863E68DE
EmsisoftDeepScan:Generic.BitcoinMiner.9.863E68DE (B)
ComodoTrojWare.Win32.Agent.evqfq@0
TrendMicroCoinminer.Win32.MALXMR.AOODAN
McAfee-GW-EditionBehavesLike.Win32.Injector.th
FireEyeDeepScan:Generic.BitcoinMiner.9.863E68DE
SophosML/PE-A + Mal/Miner-E
SentinelOneStatic AI – Malicious PE
GDataDeepScan:Generic.BitcoinMiner.9.863E68DE
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitDeepScan:Generic.BitcoinMiner.9.863E68DE
MicrosoftWorm:Win32/NeksMiner.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.BitCoinMiner.C931392
McAfeeArtemis!938150F91D74
VBA32Worm.BitMin
MalwarebytesMalware.AI.3412597764
APEXMalicious
RisingTrojan.PhotoMiner/NSIS!1.CB15 (CLASSIC)
FortinetW32/CryptoMiner.L!tr
WebrootW32.Worm.NSIS.BitMin
AVGWin32:Mykings-U [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/NeksMiner.A?

Worm:Win32/NeksMiner.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment