Worm

How to remove “Worm:Win32/Nenebra.A”?

Malware Removal

The Worm:Win32/Nenebra.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Nenebra.A virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Worm:Win32/Nenebra.A?


File Info:

crc32: 262A1615
md5: 4281806b55ffc5279b0c20fb6a534197
name: original_avatar.scr
sha1: 872130598fb08fe013841717bcce723e9d8b55a0
sha256: 09edd1870b0cdf11411a62a3f79a313212a525534fb5edf00c364de8e5948901
sha512: 8229638ee2395d59d0f8328d1691809d3d927100da8ca69af9b8909ba5b346b0e0bc3e7c3975dccd4e54214320df51ea6a3195bf9e354832a2e06fbfa950e630
ssdeep: 3072:6XKtBTMhG/dryHOSIXW9rTsZEV1vyyvBAm0w0MoqT/r+fF6Q4ya++LbAK:6XSBT9VUOqVTaU1qw50ldwQk
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Worm:Win32/Nenebra.A also known as:

MicroWorld-eScanWin32.Worm.Autorun.VX
CMCTrojan.Win32.Cosmu!O
CAT-QuickHealWorm.Nenebra.AP8
McAfeeArtemis!4281806B55FF
CylanceUnsafe
VIPRETrojan.Win32.Cosmu.xxs (v)
K7AntiVirusTrojan ( 0016e12c1 )
AlibabaWorm:Win32/Blocker.c1462679
K7GWTrojan ( 0016e12c1 )
Cybereasonmalicious.b55ffc
ArcabitWin32.Worm.Autorun.VX
BaiduWin32.Worm.Delf.ca
CyrenW32/Cosmu.KVSE-8775
SymantecW32.SillyFDC
ESET-NOD32Win32/AutoRun.Delf.HF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Cosmu-268
KasperskyTrojan-Ransom.Win32.Blocker.iwkz
BitDefenderWin32.Worm.Autorun.VX
NANO-AntivirusTrojan.Win32.Cosmu.bavxrk
ViRobotTrojan.Win32.A.Cosmu.212480[UPX]
RisingMalware.FakeFolder@CV!1.6AA9 (CLASSIC)
Endgamemalicious (moderate confidence)
EmsisoftWin32.Worm.Autorun.VX (B)
ComodoTrojWare.Win32.Cosmu.KCA@3hhp8i
F-SecureWorm.WORM/Nenebra.A
DrWebWin32.HLLW.Autoruner.57682
ZillyaWorm.Blocker.Win32.1
TrendMicroMal_OtorunO
McAfee-GW-EditionBehavesLike.Win32.Sality.dc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.4281806b55ffc527
SophosW32/AutoRun-BZI
IkarusWorm.Win32.Nenebra
F-ProtW32/Cosmu.C
JiangminTrojan/Cosmu.gje
WebrootW32.Trojan.Cosmu.Gen
AviraWORM/Nenebra.A
FortinetW32/Cosmu.XXS!tr
Antiy-AVLTrojan/Win32.Cosmu
MicrosoftWorm:Win32/Nenebra.A
SUPERAntiSpywareWorm.AutoRun/Variant
ZoneAlarmTrojan-Ransom.Win32.Blocker.iwkz
AhnLab-V3Trojan/Win32.Agent.C65479
VBA32TScope.Trojan.Delf
ALYacWin32.Worm.Autorun.VX
MAXmalware (ai score=100)
Ad-AwareWin32.Worm.Autorun.VX
MalwarebytesWorm.AutoRun
PandaGeneric Malware
ZonerTrojan.Win32.1947
TrendMicro-HouseCallMal_OtorunO
YandexTrojan.Cosmu!gKBhUwtv5Oc
SentinelOneDFI – Suspicious PE
GDataWin32.Worm.Autorun.VX
BitDefenderThetaAI:Packer.1085453F1D
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Worm.00b

How to remove Worm:Win32/Nenebra.A?

Worm:Win32/Nenebra.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment