Malware

How to remove “Win32.Malware.nmNfaqZ6I3ci”?

Malware Removal

The Win32.Malware.nmNfaqZ6I3ci is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32.Malware.nmNfaqZ6I3ci virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Installs a browser addon or extension
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32.Malware.nmNfaqZ6I3ci?


File Info:

crc32: AA52A498
md5: 3c481e7e84a50cccc1bddebb8995b000
name: 3C481E7E84A50CCCC1BDDEBB8995B000.mlw
sha1: e2bd776a1f80b99b6f348f5f07f96367bc302f04
sha256: 6e4fb318e512eff482d451555f728d174e44f3433e7eb04c89185fffc0f6826b
sha512: c4e407e9ead9d5e130b444d37b14e07cdb263374c1bafa2e1660873bb5d14cf5835647c37473b9cebee149484fafcfc76d1396157d9268976c1d87f55c7d3aef
ssdeep: 1536:vjPzy7rAVb3n3gX72IEJ5NwE4G/a3hd+g/LKl:bPzyXANQX729D4G/aR3ml
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: pikachu
FileVersion: 1.00
OriginalFilename: pikachu.exe
ProductName: Project1

Win32.Malware.nmNfaqZ6I3ci also known as:

BkavW32.PikachuGTA.Worm
K7AntiVirusP2PWorm ( 000a677e1 )
MicroWorld-eScanGen:Win32.Malware.nmNfaqZ6I3ci
CMCWorm.Win32.VB!O
CAT-QuickHealWorm.Chupik
ALYacGen:Win32.Malware.nmNfaqZ6I3ci
CylanceUnsafe
CrowdStrikemalicious_confidence_100% (W)
K7GWP2PWorm ( 000a677e1 )
Cybereasonmalicious.e84a50
TrendMicroTROJ_SPNR.03HF13
BaiduWin32.Trojan.Agent.at
NANO-AntivirusTrojan.Win32.Drop.crsvig
CyrenW32/Brontok.I.gen!Eldorado
SymantecW32.SillyFDC
ESET-NOD32Win32/VB.NSP
ZonerI-Worm.VB.NSP
TheHackerW32/VB.aso
AvastWin32:Downloader-VCO [Trj]
ClamAVLegacy.Trojan.Agent-1388589
GDataGen:Win32.Malware.nmNfaqZ6I3ci
KasperskyTrojan.Win32.Fsysna.djcx
BitDefenderGen:Win32.Malware.nmNfaqZ6I3ci
ViRobotWorm.Win32.VB.110592.B
SUPERAntiSpywareTrojan.Agent/Gen-Pikachu
TencentWorm.Win32.Autorun.d
Ad-AwareGen:Win32.Malware.nmNfaqZ6I3ci
SophosMal/VB-F
ComodoWorm.Win32.Autorun.eb0@13re4o
F-SecureGen:Win32.Malware.nmNfaqZ6I3ci
DrWebTrojan.MulDrop2.63234
ZillyaWorm.VB.Win32.2095
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dz
Trapminemalicious.high.ml.score
EmsisoftGen:Win32.Malware.nmNfaqZ6I3ci (B)
SentinelOnestatic engine – malicious
F-ProtW32/Worm.APUJ
Endgamemalicious (moderate confidence)
WebrootW32.Trojan.Gen
AviraTR/Crypt.ULPM.Gen
Antiy-AVLWorm/Win32.VB
KingsoftWorm.VB.417792.(kcloud)
MicrosoftWorm:Win32/Chupik.A
JiangminWorm/VB.auk
ArcabitGen:Win32.Malware.nmNfaqZ6I3ci
AegisLabTrojan.Win32.Fsysna.4!c
ZoneAlarmTrojan.Win32.Fsysna.djcx
AhnLab-V3HEUR/Fakon.mwf
McAfeeW32/Worm-FEL!3C481E7E84A5
MAXmalware (ai score=100)
VBA32Worm.VB
MalwarebytesTrojan.Agent
PandaW32/Picachu.A.worm
TrendMicro-HouseCallTROJ_SPNR.03HF13
RisingWorm.VobfusEx!1.99E4 (CLOUD)
YandexTrojan.ATRAPS!o3gl8DrWSl8
IkarusWorm.Win32.VB
FortinetW32/Virut.CE
AVGWin32:Downloader-VCO [Trj]
Paloaltogeneric.ml
Qihoo-360Malware.Radar01.Gen

How to remove Win32.Malware.nmNfaqZ6I3ci?

Win32.Malware.nmNfaqZ6I3ci removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment