Malware

What is “Malware.AI.112900747”?

Malware Removal

The Malware.AI.112900747 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.112900747 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.112900747?


File Info:

name: 4C17DFCBCBC331051E46.mlw
path: /opt/CAPEv2/storage/binaries/9318969f88ef3ba6988805467526150b4454b24915bba05f81cf6a68f4dbe863
crc32: B6A53BD7
md5: 4c17dfcbcbc331051e46af140baf9ac4
sha1: e1a8db658539dd27e26841f28e1c28accdd0a801
sha256: 9318969f88ef3ba6988805467526150b4454b24915bba05f81cf6a68f4dbe863
sha512: b45fd9418c1932bc45fb3d8e3093ed37f77cdffb77357fe129c9b9e1735ed85eebab704521948c6f2101c3398a6c111069f9e1ce361e845f1ad6c357c627b7f1
ssdeep: 49152:fshdzr5MoO2WRRPRjvQlM2qtXvuCoQ+qCSZ5gN5zrpzz5n0:N32WRRZr2MuCl+qCSMNd1zN0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DAB533D237F5E10FF5A716B0D146DBBC0E63D86E92351AC062B57940AF1614ECB28EAC
sha3_384: a4b850d92fc13a1eeda86d01b2a61d8dead4eebf409f26cfab354bef3b682fb1015fcf21ae6e4e4aec76665675918941
ep_bytes: 60be000068008dbe0010d8ff57eb0b90
timestamp: 2021-12-20 04:01:54

Version Info:

FileVersion: V1.0.1
Comments: 由小鱼儿yr整合绿化
FileDescription: WIN11开始菜单优化StartAllBack_v3.2.1封装专用绿色优化版
ProductVersion: 1.0
LegalCopyright: ©2018-2021 yrxitong.com 版权所有
Translation: 0x0804 0x04b0

Malware.AI.112900747 also known as:

MicroWorld-eScanTrojan.GenericKD.38688297
FireEyeGeneric.mg.4c17dfcbcbc33105
ALYacTrojan.GenericKD.38688297
MalwarebytesMalware.AI.112900747
SangforRiskware.Win32.Wacapew.C
AlibabaTrojanDropper:AutoIt/Generic.cd9ea761
Cybereasonmalicious.bcbc33
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderTrojan.GenericKD.38688297
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.38688297
EmsisoftTrojan.GenericKD.38688297 (B)
TrendMicroTROJ_FRS.VSNTB222
McAfee-GW-EditionBehavesLike.Win32.DropperAutoIt.vc
SophosGeneric PUA OB (PUA)
IkarusDropper.AutoIt
GDataTrojan.GenericKD.38688297
AviraDR/AutoIt.Gen8
Antiy-AVLTrojan/Generic.ASCommon.1B8
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftProgram:Win32/Uwamson.A!ml
CynetMalicious (score: 99)
McAfeeArtemis!4C17DFCBCBC3
MAXmalware (ai score=88)
CylanceUnsafe
TrendMicro-HouseCallTROJ_FRS.VSNTB222
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.112900747?

Malware.AI.112900747 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment