Malware

Malware.AI.3776486969 (file analysis)

Malware Removal

The Malware.AI.3776486969 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3776486969 virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Malware.AI.3776486969?


File Info:

name: E0B41B3FEF56520478B4.mlw
path: /opt/CAPEv2/storage/binaries/c9db1c200ebcc9346fb5813e804dd38bf5619083fa4a4d898bcfe1bbb7e0f9f8
crc32: 8D5E584D
md5: e0b41b3fef56520478b4d8e7cb9ffba6
sha1: 7040ede4c7ebbf37391c8d9e4e18b13da92e8d35
sha256: c9db1c200ebcc9346fb5813e804dd38bf5619083fa4a4d898bcfe1bbb7e0f9f8
sha512: 4354c1d32b17f62948c7cfea0f81a932d7ced74746585ae4d2110fd9a5b0f2139ae4299480ffa2266b6c860d65eed772680cbdfc53b9c53acbe8811d4da99cde
ssdeep: 49152:q8Z1PYEsa6Vh2y40dppn5Q8mBfMQREYRTEZH5BdjpYregKIXBuOH9FCGfSgu:TnPYDZOEpPQ8efnKYRTO9RgKMBzHU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11206F063EA180144F4D04A32CD27BDDC71F67FA94F02987F69EAB9C315364D5A2229B3
sha3_384: da0783b44270acf6a2fe289a950ce1fd9d07aaae5eb6dd0ff3396916bf0c16ce397c04b2ca0d6870a6b8b6561bc63dc4
ep_bytes: 68086e8997e8ee00fdff660fb6542500
timestamp: 2020-11-30 02:05:26

Version Info:

Comments:
CompanyName: Barunsongames Inc.
FileDescription: LastChaos Runner
FileVersion: 1, 0, 2, 1
InternalName: Nksp
LegalCopyright: Copyright ⓒ 2003-2011 Barunsongames Inc.
LegalTrademarks:
OriginalFilename: Nksp.exe
PrivateBuild:
ProductName: LastChaos
ProductVersion: 1, 0, 2, 1
SpecialBuild:
Translation: 0x0000 0x04b0

Malware.AI.3776486969 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Strictor.4!c
MicroWorld-eScanTrojan.GenericKD.68044189
FireEyeGeneric.mg.e0b41b3fef565204
ALYacTrojan.GenericKD.68044189
MalwarebytesMalware.AI.3776486969
ZillyaTrojan.VMProtect.Win32.80016
SangforTrojan.Win32.Packed.Vhw9
AlibabaPacked:Win32/VMProtect.7f9a4b93
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36318.0B0@a0luzqnP
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.ACR
APEXMalicious
BitDefenderTrojan.GenericKD.68044189
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Trojan-gen
EmsisoftTrojan.GenericKD.68044189 (B)
VIPRETrojan.GenericKD.68044189
McAfee-GW-EditionBehavesLike.Win32.BadFile.wc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.VMProtect
GDataTrojan.GenericKD.68044189
MAXmalware (ai score=81)
Antiy-AVLTrojan[Packed]/Win32.VMProtect
ArcabitTrojan.Generic.D40E459D
MicrosoftTrojan:Win32/Zpevdo.B
GoogleDetected
McAfeeArtemis!E0B41B3FEF56
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09GG23
RisingTrojan.Generic@AI.100 (RDML:sVg65RSJzfT5TY6PKpNnpA)
YandexTrojan.VMProtect!5EnVtKQGoTU
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.110168960.susgen
AVGWin32:Trojan-gen
Cybereasonmalicious.fef565
DeepInstinctMALICIOUS

How to remove Malware.AI.3776486969?

Malware.AI.3776486969 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment