Malware

What is “Malware.AI.1871332049”?

Malware Removal

The Malware.AI.1871332049 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1871332049 virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1871332049?


File Info:

name: 5154E9E9E3245790830C.mlw
path: /opt/CAPEv2/storage/binaries/6d74274a3c867e5d44ae0d2c11185d4c16a038caface85861ea08bbdb06bf6ab
crc32: 3AF1031D
md5: 5154e9e9e3245790830c7a1b9b8d8259
sha1: bd79867d213982d815ac62899966ec9ad314add7
sha256: 6d74274a3c867e5d44ae0d2c11185d4c16a038caface85861ea08bbdb06bf6ab
sha512: 543a5a7e19097f07ce4ebf573a16e49b63f886fda40fab5f90cc36cdc9aee6355e91f4acfba5acee3fa14caa30755a2baf3a801295042d16091ac3b9d8f62138
ssdeep: 49152:dFvgA2ZKB1dVjb0yzamZ7A3pI32TlEe2kzsBuHJhctyGX5XGj7Bqj39mpQ:3P/QulqfZ2kzsuHJhcvJ3Nf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126264A137634DC61FA481A37E06A43B89A381E54F874C52BF26CBC5ABF75503572AB0E
sha3_384: 7f445495bb9f2044f314a1bfe7bfb08d0ab99b06b83fcf3bc4287795305bd682ccbd727ee2093f132490b9c3613a890b
ep_bytes: 558bec6aff68a00a80006824306b0064
timestamp: 2016-06-07 05:10:32

Version Info:

FileVersion: 1.0.0.1
FileDescription: 华夏五岳
ProductName: 华夏五岳
ProductVersion: 1.0.0.1
CompanyName: 北京飞龙财富网
LegalCopyright: 本程序著作权归属王凤龙所有,本系统受版权法保护,未经授权不得擅自拷贝和传播软件的全部或部分内容,不得擅自进行修改,否则将受到严厉的法律制裁。
Comments: 华夏五岳
Translation: 0x0804 0x04b0

Malware.AI.1871332049 also known as:

LionicTrojan.Win32.Generic.lqH9
Elasticmalicious (high confidence)
ClamAVWin.Malware.Trojanx-9951053-0
FireEyeGeneric.mg.5154e9e9e3245790
McAfeeArtemis!5154E9E9E324
MalwarebytesMalware.AI.1871332049
SangforTrojan.Win32.Agent.V39z
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojan:Win32/BScope.0b56d1ea
K7GWTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaF.36250.@t0@aan5JUlH
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
McAfee-GW-EditionBehavesLike.Win32.Generic.rh
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.4AIOBO
WebrootW32.Adware.Gen
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32BScope.Trojan.Casur
Cylanceunsafe
RisingTrojan.Generic@AI.99 (RDMK:cmRtazpjxMPh/xo/FX11g9kd08jV)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.d21398
DeepInstinctMALICIOUS

How to remove Malware.AI.1871332049?

Malware.AI.1871332049 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment