Malware

Malware.AI.1933656249 removal instruction

Malware Removal

The Malware.AI.1933656249 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1933656249 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1933656249?


File Info:

name: 37B056C6451C1220BB72.mlw
path: /opt/CAPEv2/storage/binaries/9d8356665e66098e14f6facfe5b6572159d2ce38e1701f3795a6459361745d07
crc32: 4D37E663
md5: 37b056c6451c1220bb72214f3ec6d5a8
sha1: 2566a67f4d7ea1727d9f9dd3d058651958db4f19
sha256: 9d8356665e66098e14f6facfe5b6572159d2ce38e1701f3795a6459361745d07
sha512: 82ae8fe3ea53213cd07179f0953a68d0994d6d43026dc5973918df12203ab3311446931cafadf7813977178e24a49147b4ffd8519de60ee3c3eff42ba0d9c1e2
ssdeep: 12288:bR8UobqPnrsNmBgj28ZpH+JGom6b7MP+Dd2:btdaogjfZksC7MP+h2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147A42288A995D94CCD3A793573738A34D3A1EE71EE8A900FB2FF7AE81E344804C54656
sha3_384: 33a4ba17b662c9a67077cb0cfa1d457fbdef24d72485da48c6fdbce93c9fa8a6c10a132f274741a71c62e6d56a757174
ep_bytes: 6801605300e801000000c3c3ffdf1b62
timestamp: 2007-06-03 14:43:58

Version Info:

Translation: 0x0804 0x04b0
Comments: http://www.superrsoft.com
CompanyName: Super Rabbit Soft
FileDescription: http://www.superrsoft.com
LegalCopyright: Cai Xuan
LegalTrademarks: Super Rabbit
ProductName: Super Rabbit Network Expert Client
FileVersion: 7.99
ProductVersion: 7.99
InternalName: sriecli
OriginalFilename: sriecli.exe

Malware.AI.1933656249 also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Black.x!c
MicroWorld-eScanTrojan.GenericKD.69924668
FireEyeGeneric.mg.37b056c6451c1220
SkyhighBehavesLike.Win32.Trojan.gc
McAfeeArtemis!37B056C6451C
MalwarebytesMalware.AI.1933656249
ZillyaTrojan.FakeAV.Win32.307017
SangforTrojan.Win32.Packed.V2xn
K7AntiVirusTrojan ( 0055e39b1 )
AlibabaPacked:Win32/Black.b452ccb1
K7GWTrojan ( 0055e39b1 )
ArcabitTrojan.Generic.D42AF73C
VirITTrojan.Win32.Generic.BNFI
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Packed.ASProtect.AAB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Black-9804544-0
KasperskyPacked.Win32.Black.d
BitDefenderTrojan.GenericKD.69924668
AvastWin32:MalwareX-gen [Trj]
EmsisoftTrojan.GenericKD.69924668 (B)
F-SecureHeuristic.HEUR/AGEN.1368914
VIPRETrojan.GenericKD.69924668
TrendMicroTROJ_GEN.R002C0RJQ23
Trapminemalicious.moderate.ml.score
SophosMal/Behav-270
IkarusWorm.Win32.AutoRun
JiangminPacked.Black.aoan
AviraHEUR/AGEN.1368914
Kingsoftmalware.kb.a.998
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmPacked.Win32.Black.d
GDataTrojan.GenericKD.69924668
GoogleDetected
ALYacTrojan.GenericKD.69924668
MAXmalware (ai score=89)
VBA32BScope.Trojan.Tiggre
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0RJQ23
YandexTrojan.ASProtect!3MhobgoGqHg
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1933656249?

Malware.AI.1933656249 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment