Malware

Malware.AI.154799632 removal tips

Malware Removal

The Malware.AI.154799632 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.154799632 virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.154799632?


File Info:

name: D1B6B4E583F3FF1D4C93.mlw
path: /opt/CAPEv2/storage/binaries/ccd619cce20eab2718700f017a7d4654e1d48d5f6d31116d2c142973a5f2b78e
crc32: 73C259F0
md5: d1b6b4e583f3ff1d4c930baad1bb4659
sha1: a769f3a42f10f81ee6bc96097beaaf46f07cfdcd
sha256: ccd619cce20eab2718700f017a7d4654e1d48d5f6d31116d2c142973a5f2b78e
sha512: 20fe2d7bf6c8863fd4faf72bb8161a131a09e440302b9677c4b626663f294a316b6a920afa8a6a27215105e458209507d07c21b630d57577c6a9256b21cc7524
ssdeep: 3072:yQFFO8NPqFJTFckfVL092f1MZW/uxRZpj6bwZHCoLpFg:yQ3cFh1bdM02C+PL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T196447C30F7EBC2B2CA9711F110FA972E6A36AE41232095D3D7581F4B9D552C1793D24E
sha3_384: 3ee105a8dff62df3f5093d58313010ebe25f70c0b0f35ba80231eb04119fb902fc5d32989e8f4f4065d779a15a75f4e9
ep_bytes: e844290000e916feffff558bec81ec28
timestamp: 2006-10-17 19:03:59

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 4.42
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2006 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 4.42

Malware.AI.154799632 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.70659252
CAT-QuickHealTrojan.Agent
SkyhighArtemis
McAfeeArtemis!D1B6B4E583F3
MalwarebytesMalware.AI.154799632
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/dUmPeX.b7f929da
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_70% (D)
ArcabitTrojan.Generic.D4362CB4
Elasticmalicious (moderate confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.70659252
AvastWin32:dUmPeX [Susp]
SophosMal/Generic-S
VIPRETrojan.GenericKD.70659252
EmsisoftTrojan.GenericKD.70659252 (B)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=87)
Kingsoftmalware.kb.a.973
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.70659252
VaristW32/ABRisk.ACYW-4505
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09L823
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.221151103.susgen
FortinetW32/PossibleThreat
AVGWin32:dUmPeX [Susp]
Cybereasonmalicious.42f10f
DeepInstinctMALICIOUS

How to remove Malware.AI.154799632?

Malware.AI.154799632 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment