Malware

What is “Malware.AI.1789094282”?

Malware Removal

The Malware.AI.1789094282 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1789094282 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Malware.AI.1789094282?


File Info:

name: 627EAA6D9346181DB6A5.mlw
path: /opt/CAPEv2/storage/binaries/d4a2316c714757eee4639b43b274cf45176550409e2210bea7e2c0a9c9f86cab
crc32: FF29031D
md5: 627eaa6d9346181db6a536bb73e0073a
sha1: 558ebd0d8e62d815022b5ed6cbe4cdcbdd9b24e2
sha256: d4a2316c714757eee4639b43b274cf45176550409e2210bea7e2c0a9c9f86cab
sha512: ddf80fda69a61b0adce80bc4b2c0223634d55c9aa60eca5103a0e6c163ed720e6532ede7f8640e824431e2d58c250027561f282234fb6f0a787c95ce4f960290
ssdeep: 49152:Lx4Yttpd3SXxpFhLs4qH3v865HHKLiF3Khhnvs:LxBT3o3hLs4qXU6NqmF3I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108859E22B791C076C233317196CBA3B9B6EAE5315E35428B5AC01F382E754D3993D62F
sha3_384: 9d1eb3fa29a36b9a4f35ac3f1216d11a4e9ff1c5249c9d993b5d9a1e913bfb970fecf8d4fe37f03b14bf50906c4736d7
ep_bytes: e837800000e979feffff3b0d40595900
timestamp: 2019-09-05 07:11:39

Version Info:

FileVersion: 33.2.1.5
InternalName: pptUp.exe
OriginalFilename: pptUp.exe
ProductVersion: 33.2.1.5
Translation: 0x0804 0x03a8

Malware.AI.1789094282 also known as:

LionicAdware.Win32.KuwanBar.2!c
MicroWorld-eScanGen:Variant.Application.Bundler.YouXun.3
ALYacGen:Variant.Application.Bundler.YouXun.3
ZillyaTool.YouXun.Win32.658
K7AntiVirusRiskware ( 005598371 )
AlibabaRiskWare:Win32/YouXun.2b60e9c4
K7GWRiskware ( 005598371 )
Cybereasonmalicious.d93461
CyrenW32/S-41c29a99!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/RiskWare.YouXun.AC
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.KuwanBar.gen
BitDefenderGen:Variant.Application.Bundler.YouXun.3
NANO-AntivirusRiskware.Win32.YouXun.hsyxui
AvastWin32:Malware-gen
TencentUw:Adware.Win32.Zusy.yb
Ad-AwareGen:Variant.Application.Bundler.YouXun.3
EmsisoftGen:Variant.Application.Bundler.YouXun.3 (B)
TrendMicroTROJ_GEN.R002C0PKP21
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGen:Variant.Application.Bundler.YouXun.3
SophosGeneric PUA FF (PUA)
GDataGen:Variant.Application.Bundler.YouXun.3
JiangminAdWare.KuwanBar.bb
MAXmalware (ai score=76)
Antiy-AVLTrojan/Generic.ASMalwS.30D0168
KingsoftWin32.Troj.Generic.yz.(kcloud)
ViRobotAdware.Youxun.1830400
MicrosoftTrojan:Win32/Ymacco.ABD4
AhnLab-V3Malware/Win32.Generic.R372540
McAfeeGenericR-QXV!627EAA6D9346
VBA32BScope.Trojan.FakeAlert
MalwarebytesMalware.AI.1789094282
TrendMicro-HouseCallTROJ_GEN.R002C0PKP21
RisingAdware.YouXun!1.D190 (CLASSIC)
YandexPUA.KuwanBar!6pB+3Sh0cx4
FortinetRiskware/YouXun
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Malware.AI.1789094282?

Malware.AI.1789094282 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment