Malware

Malware.AI.1660835612 removal instruction

Malware Removal

The Malware.AI.1660835612 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1660835612 virus can do?

  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.1660835612?


File Info:

name: 14C1BAF12A84D67F6AB7.mlw
path: /opt/CAPEv2/storage/binaries/c7abe57af7911bf9ff64eddadc980154108a7bd2232b6dd3ced3b8495a9d7005
crc32: C4A0C532
md5: 14c1baf12a84d67f6ab7ed4c5fde188d
sha1: aa8a230fb56a2458e4314fac8c9ecf89057a910b
sha256: c7abe57af7911bf9ff64eddadc980154108a7bd2232b6dd3ced3b8495a9d7005
sha512: d23a0a112a41bfef5280003d5a1effb0b2bbedbbb473de65667f1389ed8e5a5f484dfe69bd4f31c4b415eb32937f8ec413cb7581e74fb1f595f91b2ed5854798
ssdeep: 24576:fOF9PyCDle8th4MljzPhJJIhFNWqQi651eNqAbXBgBnSSd7WKFy7DVhdXoGRkK3N:U9Plle8Bjr0WzGbRg5SSd78V/YGRkC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126A55C23B245263AC4AB07394727EA64DC3F7B213A468C1F57F0185CCE356856E3E66B
sha3_384: 72212fa2634c479eb92f55597a7dc0a7c33085e7b04f43b9c0748c9042ffbe6f414e3bb8fa29338c7ac11f94252a6f25
ep_bytes: 558bec83c4f0b824a25d00e874a5e2ff
timestamp: 2019-10-24 12:23:54

Version Info:

CompanyName: 51沪牌
FileDescription: 51沪牌拍牌浏览器
FileVersion: 1.0.0.0
LegalCopyright: 51沪牌版权所有
ProductVersion: 1.0.0.0
Translation: 0x0804 0x03a8

Malware.AI.1660835612 also known as:

LionicAdware.Win32.Generic.2!c
FireEyeGen:Variant.Jacard.66937
McAfeeArtemis!14C1BAF12A84
CylanceUnsafe
ZillyaAdware.Generic.Win32.136917
SangforAdware.Win32.Generic.ky
AlibabaAdWare:Win32/Generic.f99b7275
Cybereasonmalicious.12a84d
BitDefenderThetaAI:Packer.F8819C9318
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H0CIJ21
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Jacard.66937
MicroWorld-eScanGen:Variant.Jacard.66937
TencentWin32.Adware.Generic.Dzaf
SophosGeneric PUA KK (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
EmsisoftGen:Variant.Jacard.66937 (B)
JiangminAdWare.Generic.tsax
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.CC7
GDataGen:Variant.Jacard.66937
SentinelOneStatic AI – Suspicious PE
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Jacard.66937
MalwarebytesMalware.AI.1660835612
APEXMalicious
RisingTrojan.Fuery!8.EAFB (CLOUD)
YandexTrojan.GenAsa!zwzj5lmh2O4
MAXmalware (ai score=82)
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Generic
PandaTrj/GdSda.A

How to remove Malware.AI.1660835612?

Malware.AI.1660835612 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment