Malware

Should I remove “Malware.AI.1511059954”?

Malware Removal

The Malware.AI.1511059954 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1511059954 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Sniffs keystrokes

How to determine Malware.AI.1511059954?


File Info:

name: 3A182C349F92D543B87A.mlw
path: /opt/CAPEv2/storage/binaries/f511192b5b80e4f877dd9d4315c8d09551302e139eb971b9440c17e396498d5f
crc32: 5D0B751B
md5: 3a182c349f92d543b87a2b153c21ee88
sha1: 9ee98781761161475442c7e3d0455b4934e78ccc
sha256: f511192b5b80e4f877dd9d4315c8d09551302e139eb971b9440c17e396498d5f
sha512: 1286a53544390a090d2cd898ab4c0d0c54a15306fecc2b1ef08940f9767500ade54f31ed8ed61fa8a70c30772ca1923d7b2534d2c0f95a53ca0a4336609c32e6
ssdeep: 384:PyJUg+1MvN3t2qO7Kj8kPe/+wD8t9AA4oJZ6UpbP5JJwJJJJJJxJJl:qSiV3t2qXEtD8t94qjP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T165923B071F3CC5D4E6C5E0310965A86430FCB82710EA9FE166C74E16BEADD7E25A0BAC
sha3_384: be44fbe5bf4d50c9873ccad97e69bdb2dd8685552165882925c2e56eb436399909fe8a4cf8e0a97e6bcc88a1319a1dae
ep_bytes: 60be00c040008dbe0050ffff5783cdff
timestamp: 2005-04-16 02:15:53

Version Info:

0: [No Data]

Malware.AI.1511059954 also known as:

LionicTrojan.Win32.FreeTrip.4!c
MicroWorld-eScanTrojan.GenericKD.4471257
ALYacTrojan.GenericKD.4471257
CylanceUnsafe
SangforTrojan.PDF.GenericKD.4
K7AntiVirusUnwanted-Program ( 004b96c61 )
K7GWUnwanted-Program ( 004b96c61 )
Cybereasonmalicious.49f92d
VirITI-WORM.Win32.FreeTrip.DS
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/GameHack.G potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002C0OB622
BitDefenderTrojan.GenericKD.4471257
NANO-AntivirusTrojan.Win32.FreeTrip.gxzyu
Ad-AwareTrojan.GenericKD.4471257
SophosGeneric PUA JO (PUA)
ZillyaWorm.FreeTrip.Win32.57
TrendMicroTROJ_GEN.R002C0OB622
McAfee-GW-EditionBehavesLike.Win32.PUP.mh
FireEyeTrojan.GenericKD.4471257
EmsisoftTrojan.GenericKD.4471257 (B)
GDataTrojan.GenericKD.4471257
JiangminWorm/FreeTrip.ai
Antiy-AVLTrojan/Generic.ASMalwS.4B3024
KingsoftWin32.Malware.Heur_Generic.A.(kcloud)
ArcabitTrojan.Generic.D4439D9
ViRobotI-Worm.Win32.A.FreeTrip.20480.A[UPX]
MicrosoftTrojan:AndroidOS/Mploit!rfn
McAfeeArtemis!3A182C349F92
MAXmalware (ai score=93)
VBA32BScope.Trojan.Tiggre
MalwarebytesMalware.AI.1511059954
APEXMalicious
RisingTrojan.Occamy!8.F1CD (CLOUD)
MaxSecureTrojan.Malware.1552757.susgen
FortinetW32/Malware_fam.NB
PandaTrj/CI.A

How to remove Malware.AI.1511059954?

Malware.AI.1511059954 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment