Malware

About “WAT:Blacked-M” infection

Malware Removal

The WAT:Blacked-M is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What WAT:Blacked-M virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.milionariosnett.com

How to determine WAT:Blacked-M?


File Info:

crc32: C83C2372
md5: 15efc963e6793ea3cd55a620ff439855
name: 15EFC963E6793EA3CD55A620FF439855.mlw
sha1: 4ae6b378ab8cdc3628e149a4a6ffe5c841cd8451
sha256: dfdb23a5bd58da2ee65abee4886ef7ccfd1022898e2633e1d34f2701f23772f8
sha512: 0ec142709d9b65996912d5759bd5d862e78b558ef62804b85a3ec6161764ca7b8a8575bdcafc7c3837407b9c7c9856eb9efffc451c0b3509dfb52fccf520cbf3
ssdeep: 12288:lr1KRx+zmgZd0z6bh/6cIDc+o0jVgIeJhIL3s30FOe4p4q9:lr12x+5ZdMoEcpmgIwhIQkV4pb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: atualizador.exe
FileVersion: 1.0.0.1
CompanyName: Atualizaxe7xe3o de Protexe7xe3o ao Cliente.
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.1
FileDescription: Atualizaxe7xe3o de Seguranxe7a.
OriginalFilename: Atualizador
Translation: 0x0416 0x04e4

WAT:Blacked-M also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.MulDrop8.30567
CynetMalicious (score: 100)
SangforTrojan.Win32.Blacked.M
AlibabaTrojanPSW:Win32/Azorult.69b29eb4
Cybereasonmalicious.8ab8cd
SymantecML.Attribute.HighConfidence
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWAT:Blacked-M
KasperskyHEUR:Trojan-PSW.Win32.Azorult.vho
NANO-AntivirusTrojan.Win32.Banload.ffmszq
TencentWin32.Trojan-downloader.Banload.Eaeh
SophosMal/Generic-S
ComodoMalware@#4e0qsy6sqky4
BitDefenderThetaGen:NN.ZexaF.34170.JO1aaKPef1oG
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
FireEyeGeneric.mg.15efc963e6793ea3
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1116065
MicrosoftTrojan:Win32/Wacatac.A!ml
AhnLab-V3Trojan/Win32.Banload.C2649732
McAfeeArtemis!15EFC963E679
MAXmalware (ai score=94)
VBA32TScope.Trojan.Delf
PandaTrj/CI.A
YandexTrojan.GenAsa!w/WjDpMUtkw
FortinetW32/PossibleThreat
AVGWAT:Blacked-M
Paloaltogeneric.ml

How to remove WAT:Blacked-M?

WAT:Blacked-M removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment