Malware

Malware.AI.1891704101 removal instruction

Malware Removal

The Malware.AI.1891704101 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1891704101 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1891704101?


File Info:

name: 68A6A0CAA00E1EB9390C.mlw
path: /opt/CAPEv2/storage/binaries/9a3920524519d7a99026814a987bd642968782260325d544a1feb3209925f674
crc32: 6E52A1E6
md5: 68a6a0caa00e1eb9390c5c123a19ab0f
sha1: e05617b3fc299ce0614710d18449bbe8ada0ae59
sha256: 9a3920524519d7a99026814a987bd642968782260325d544a1feb3209925f674
sha512: 56bc76296a2763bdc2f7c6d6b5c42b86c4e5cd760bf43c8d222150c6f070a3ac3149d3d9d456b7f9923c91ce821b16d3ffd5d607f52aaa784c281829bbad6d6f
ssdeep: 24576:x4R3r9sWFBfP6UdW3UllPgC5O9BX1H3zA:x4FTLOAc9BX1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C25DF462270C697D0203274CD9EBBF46221AFEBEC528A07F650FE5EF9F1F851952246
sha3_384: a197d5ef1955fa1ba5955ee3af7242e52ebe6e97bfdbf88890bc353dd5da93d31a645267b6d4e33826ff211e3324b782
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2022-06-28 13:31:27

Version Info:

FileVersion: 1.1.0.0
FileDescription: CrossFire Data Finder
ProductName: CrossFire Data Finder
ProductVersion: 1.1.0.0
LegalCopyright: 本软件仅供交流与学习使用
Comments:
Translation: 0x0804 0x04b0

Malware.AI.1891704101 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FlyStudio.4!c
tehtrisGeneric.Malware
FireEyeGeneric.mg.68a6a0caa00e1eb9
SkyhighBehavesLike.Win32.Generic.dc
MalwarebytesMalware.AI.1891704101
SangforTrojan.Win32.Agent.Vbw8
AlibabaTrojan:Win32/OnlineGames.f9ba5fdb
Cybereasonmalicious.3fc299
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Trojanx-9951053-0
AvastWin32:Malware-gen
SophosGeneric Reputation PUA (PUA)
Trapminemalicious.moderate.ml.score
IkarusPUA.FlyStudio
VaristW32/OnlineGames.HI.gen!Eldorado
Antiy-AVLTrojan[Packed]/Win32.FlyStudio
Kingsoftmalware.kb.a.999
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5295669
McAfeeRDN/Generic.dx
VBA32BScope.Trojan.Dynamer
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H06E523
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
BitDefenderThetaGen:NN.ZexaF.36792.9y0baGBA41oH
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.1891704101?

Malware.AI.1891704101 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment