Malware

Malware.AI.1942734061 (file analysis)

Malware Removal

The Malware.AI.1942734061 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1942734061 virus can do?

  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Malware.AI.1942734061?


File Info:

name: F88DC42D80452A9B3323.mlw
path: /opt/CAPEv2/storage/binaries/2d89fa9ed5e47b09e14587e96cce4c6a7a99554227fbda456d2da5ec8f1affcf
crc32: 35C2F097
md5: f88dc42d80452a9b3323ecc3f229638f
sha1: d9ffebea288d8f996c6a0c59682b4bd804c4a481
sha256: 2d89fa9ed5e47b09e14587e96cce4c6a7a99554227fbda456d2da5ec8f1affcf
sha512: 2e68fda72b4191d0447afcc9715b518bd0a6a5ea7efb8525487acbd1d9399fc67b1b27a60cfbbb06e49431375c203004c8c24b549370b92788b2625f124b6282
ssdeep: 6144:vskXWPJIOrl6bNGPZSSDl+we5vVq2LGaOGS9yUbxb8uhgR4/F+6HzoXa9fkgz:vsfrl4Oo5vtOGS9DbOqgA44zo6f/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7A4F71AF9D20907D6262771D6EA5E3097264CD23287EF3E67E223D12C8339F95C84E5
sha3_384: 2f5ad4a3db14675702332121188baad48c5c49f20a8608d82ff465dd6f1d6ee32e8a8d2e078a35d3754367bc785813c1
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-10-07 19:24:36

Version Info:

Translation: 0x0000 0x04b0
Comments: Bandicam - bdcam.exe
CompanyName: Bandicam Company
FileDescription: Bandicam - bdcam.exe
FileVersion: 4.6.4.1728
InternalName: Spoofer.exe
LegalCopyright: Copyright(c) 2009-2020 Bandicam.com All rights reserved.
OriginalFilename: Spoofer.exe
ProductName: bdcam
ProductVersion: 4.6.4.1728
Assembly Version: 4.6.4.1728

Malware.AI.1942734061 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.KillProc2.12323
MicroWorld-eScanGen:Variant.Razy.789220
FireEyeGeneric.mg.f88dc42d80452a9b
ALYacGen:Variant.Razy.789220
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforInfostealer.MSIL.Maslog.gen
K7AntiVirusTrojan ( 00570ad81 )
AlibabaTrojanPSW:MSIL/Maslog.6a0116f8
K7GWTrojan ( 00570ad81 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.34114.Cm2@aOsd5og
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.YCG
TrendMicro-HouseCallTROJ_GEN.R002C0GLB21
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Maslog.gen
BitDefenderGen:Variant.Razy.789220
NANO-AntivirusTrojan.Win32.Maslog.hzesgc
TencentWin32.Trojan.Falsesign.Eehh
Ad-AwareGen:Variant.Razy.789220
EmsisoftGen:Variant.Razy.789220 (B)
ZillyaTrojan.Kryptik.Win32.2588719
TrendMicroTROJ_GEN.R002C0GLB21
McAfee-GW-EditionArtemis
SophosMal/Generic-S
Paloaltogeneric.ml
GDataGen:Variant.Razy.789220
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1138926
Antiy-AVLTrojan/MSIL.Kryptik
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Razy.DC0AE4
MicrosoftTrojan:Win32/Ymacco.AA2D
CynetMalicious (score: 99)
McAfeeArtemis!F88DC42D8045
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.1942734061
APEXMalicious
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat.PALLAS.H
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.d80452
PandaTrj/GdSda.A

How to remove Malware.AI.1942734061?

Malware.AI.1942734061 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment