Malware

About “Malware.AI.1057190701” infection

Malware Removal

The Malware.AI.1057190701 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1057190701 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1057190701?


File Info:

name: CC6896AA6AF22F44D86F.mlw
path: /opt/CAPEv2/storage/binaries/6da0ef1396a97a1c05b5b35b0ce6e1b27a7c6c9eac5d382df675669563d3e6fe
crc32: A51A8A04
md5: cc6896aa6af22f44d86f90e14b407fd6
sha1: de8a4c902d21c1f5353be4035edc3e0ed5c5b11f
sha256: 6da0ef1396a97a1c05b5b35b0ce6e1b27a7c6c9eac5d382df675669563d3e6fe
sha512: 7ce41740c2506c876476251475b8b370e6aec7a9834cf55b661098d4df0e4b014148b47d23263d64ee9aef3dda0f9dfd22700f5f3314779c8c715e8c5684d1fa
ssdeep: 12288:7p7XA6ZUjPz5ALznqZaBQT89yNNpDEF81hNnvsGx7S7w7e7:ZXAZPz5ALzrK89yNNpDw81hNnv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153D404025B898C01C96586F7C8664A771372FD346B229AB94F947CEBBF721ADD843073
sha3_384: 4ebff3bdc0ab5149d8d0c2118cccd459adac75ea31b5f60ecf5e670281db9731501e67d5477324c6c3f850b745c20ab9
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2023-02-21 10:25:29

Version Info:

Comments:
CompanyName: YT Applications
FileDescription: YT Player
FileVersion: 7, 22, 1, 0
InternalName: YT Player
LegalCopyright: (C) YT Applications. All rights reserved.
LegalTrademarks:
OriginalFilename: YTPlayer.EXE
PrivateBuild:
ProductName: YT Downloader
ProductVersion: 7, 22, 1, 0
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.AI.1057190701 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.cc6896aa6af22f44
McAfeeGenericRXAA-AA!CC6896AA6AF2
MalwarebytesMalware.AI.1057190701
SangforTrojan.Win32.Agent.Vg4o
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Generic-9951959-0
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.high.ml.score
WebrootW32.Trojan.Genkd
Antiy-AVLTrojan/Win32.SGeneric
GoogleDetected
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.36348.Lmuaam60cjai
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.1057190701?

Malware.AI.1057190701 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment