Malware

Malware.AI.1901457648 removal tips

Malware Removal

The Malware.AI.1901457648 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1901457648 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.1901457648?


File Info:

name: A5104979BFB6BC7E190C.mlw
path: /opt/CAPEv2/storage/binaries/62e25b4605a9515c413ec580caa41d201d6bd044788ce1803258ba5577375803
crc32: 64E3A15B
md5: a5104979bfb6bc7e190c529fb36da1c4
sha1: 1bc8e227dc2cb100f9e57216d5e9f4b56365b6a2
sha256: 62e25b4605a9515c413ec580caa41d201d6bd044788ce1803258ba5577375803
sha512: bf5ac80f706ac2391deeb77faa0c81ea0638e6cfb9d496b704a2eb7d0aa86b0396d8794e5faf86cd674f2fb469a76555b2ae2b25aef022e3215944e4bfcd49ee
ssdeep: 12288:FA8JgXrAFma8LGrhA8JgXsflsXSLZ+woBZtjbCJ+x7RJFJI6QenC5fjiT7qbKP6v:NgXkeGFgXo7LMwogJ+xBQBffKzZ9spl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T128350222FF106211E15B45B1187685BA3A2A7C3405111E077680EE6DBCB2AA7FCF677F
sha3_384: 61c8e8c85dc7ab09aec50f2df93a5c861d976d72e84007c8667da3f5ecb52e0dfd612ea870c4608e6241e8caf97ce739
ep_bytes: 68d8244000e8eeffffff000040000000
timestamp: 2010-08-27 11:48:59

Version Info:

Translation: 0x0804 0x04b0
Comments: 作者:东东 E-Mail:liuhaodong115@qq.com (此文件为“文件加密助手”所加密的文件,需输入正确的密码才能解密)
CompanyName: 明官店电脑售后服务中心
FileDescription: 已被加密的数据·需输入正确的密码进行解密。(非常欢迎您的破解o(∩_∩)o)
ProductName: 被加密的文件
FileVersion: 2.02
ProductVersion: 2.02
InternalName: Encrypt
OriginalFilename: Encrypt.exe

Malware.AI.1901457648 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.408537
FireEyeGeneric.mg.a5104979bfb6bc7e
SkyhighBehavesLike.Win32.Autorun.tc
ALYacGen:Variant.Lazy.408537
Cylanceunsafe
VIPREGen:Variant.Lazy.408537
SangforTrojan.Win32.Lazy.Vm03
BitDefenderGen:Variant.Lazy.408537
Cybereasonmalicious.7dc2cb
SymantecML.Attribute.HighConfidence
APEXMalicious
NANO-AntivirusTrojan.Win32.VB.ekuzwd
F-SecureHeuristic.HEUR/AGEN.1348242
DrWebTrojan.VbCrypt.250
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Lazy.408537 (B)
MAXmalware (ai score=80)
GoogleDetected
AviraHEUR/AGEN.1348242
VaristW32/S-e492f7c2!Eldorado
Antiy-AVLTrojan/Win32.SGeneric
Kingsoftmalware.kb.a.992
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Lazy.D63BD9
GDataGen:Variant.Lazy.408537
CynetMalicious (score: 99)
McAfeeArtemis!A5104979BFB6
DeepInstinctMALICIOUS
VBA32TScope.Trojan.VB
MalwarebytesMalware.AI.1901457648
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R011H0CJE23
YandexTrojan.GenAsa!nshtf0vxdPY
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.219065936.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZevbaF.36792.gn3@aGfDpfab
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.1901457648?

Malware.AI.1901457648 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment