Malware

Malware.AI.2020781462 removal guide

Malware Removal

The Malware.AI.2020781462 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2020781462 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2020781462?


File Info:

name: C0C939DDDF3D0F572404.mlw
path: /opt/CAPEv2/storage/binaries/61d65ff51995c48abfb02140426745d547ad3b34f0046c1fa92146693704fed6
crc32: 3F7B316F
md5: c0c939dddf3d0f572404933f50612c6d
sha1: 72e55a973f75e38c32a7f5d325200b282fdf63ff
sha256: 61d65ff51995c48abfb02140426745d547ad3b34f0046c1fa92146693704fed6
sha512: 078a9df573c2db33adae23cebcd056737bfb272a09210013590a82b65a96bdcad84bc3b2dcb3bb16db7a73d5471fca4872f55acb1e560e7f0ea4ba378de0fd1c
ssdeep: 1536:1HxVksqo/Edk26NfZ6SZSSOWaBFqTjgbHtM1yezrg8GHb4+J62oTTEL/DlsQ851H:XL/ErSdOKkbHtInyG2mTmGQ9AphKElM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1632441A5B69318D4D952DDB97583F3DF883A30647A331092C31627A9CD24F809B2C9BF
sha3_384: e073638151aaac85870718b41743cf141fdf14383bb90e80e38ae2d7c2a01b40ee83a4a5f76d7c5e1ddb480c130f4ace
ep_bytes: 68d4124000e8eeffffff000000000000
timestamp: 2011-01-18 15:32:13

Version Info:

Translation: 0x0409 0x04b0
CompanyName: onARP15
ProductName: onARP7313
FileVersion: 1.21
ProductVersion: 1.21
InternalName: onARP15
OriginalFilename: onARP15.exe

Malware.AI.2020781462 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.VBKrypt.23
FireEyeGeneric.mg.c0c939dddf3d0f57
CAT-QuickHealWorm.WbnaMF.S28717735
MalwarebytesMalware.AI.2020781462
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan-Downloader ( 001ff72a1 )
K7GWTrojan-Downloader ( 001ff72a1 )
Cybereasonmalicious.ddf3d0
BaiduWin32.Worm.AutoRun.cj
VirITWorm.Win32.VB.13.AR
CyrenW32/VB.BR.gen!Eldorado
SymantecW32.Changeup!gen10
tehtrisGeneric.Malware
ESET-NOD32Win32/AutoRun.VB.ZL
TrendMicro-HouseCallWORM_VBNA.SMTB
ClamAVWin.Trojan.VB-1608
KasperskyWorm.Win32.WBNA.ipa
BitDefenderGen:Variant.VBKrypt.23
NANO-AntivirusTrojan.Win32.VB.chzviq
SUPERAntiSpywareTrojan.Agent/Gen-IRCNite
AvastWin32:VB-QTS [Drp]
TencentWorm.Win32.Wbna .16000410
SophosMal/SillyFDC-D
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner2.24550
VIPREGen:Variant.VBKrypt.23
TrendMicroWORM_VBNA.SMTB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.VBKrypt.23 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.VBKrypt.23
JiangminWorm/VBNA.gwky
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumWorm.Win32.Vobfus.C@2ohzew
ArcabitTrojan.VBKrypt.23
ViRobotWorm.Win32.A.VBNA.212992.H
ZoneAlarmWorm.Win32.WBNA.ipa
MicrosoftTrojanDownloader:Win32/Agent
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.VBNA.R118538
Acronissuspicious
BitDefenderThetaAI:Packer.65E76ED520
TACHYONTrojan/W32.VB-VBKrypt.212992.G
VBA32Trojan.VBRA.03035
Cylanceunsafe
PandaW32/Vobfus.GET.worm
APEXMalicious
RisingTrojan.Win32.VBCode.cdq (CLASSIC)
IkarusGen.Variant.VBKrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoRun.XM!worm
AVGWin32:VB-QTS [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.2020781462?

Malware.AI.2020781462 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment