Malware

About “Malware.AI.1951612991” infection

Malware Removal

The Malware.AI.1951612991 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1951612991 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1951612991?


File Info:

name: 5FF9C89933A66185E2F1.mlw
path: /opt/CAPEv2/storage/binaries/46e151c9b813c8d9a06ecd3e10abd04c9d6451e40ad5eb9d7d8e5eff6ac97426
crc32: FF71BD92
md5: 5ff9c89933a66185e2f13648e7d7cecf
sha1: ce2860ae22594e889e5c417cf599db19119ec884
sha256: 46e151c9b813c8d9a06ecd3e10abd04c9d6451e40ad5eb9d7d8e5eff6ac97426
sha512: 75bdc8814e1590315c0d15ff7b8a897efcacf1c61328ca320275d1ffe8af988773cddb4650c504745eba2861ec453abd2dce7004a071160dd2e7d8c752e52663
ssdeep: 1536:AcdOsaY8ECgZCbyKXYkzEdyjIzMQUn3Zu6xgU12W:m4CuCbyKjodOn3c01v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11A53F183D71A94A4C0884E3280ECB5D667439D27C371FC0FD5B2BA825BF66E5B530947
sha3_384: 07f5daafe30926826e1c13a7a9b003f1d04998672b716d65dd3df7324b7b321c969f0021227272ff110c7dd1995dc52c
ep_bytes: 558bec6aff6880204000686017400064
timestamp: 2008-08-13 16:30:35

Version Info:

0: [No Data]

Malware.AI.1951612991 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.kYLC
MicroWorld-eScanTrojan.Dropper.SIS
FireEyeGeneric.mg.5ff9c89933a66185
CAT-QuickHealTrojanDropper.Dooxud.A8
SkyhighBehavesLike.Win32.VirRansom.kc
ALYacTrojan.Dropper.SIS
MalwarebytesMalware.AI.1951612991
VIPRETrojan.Dropper.SIS
SangforSuspicious.Win32.Save.ins
BitDefenderTrojan.Dropper.SIS
Cybereasonmalicious.e22594
BitDefenderThetaAI:Packer.77569B171E
VirITBackdoor.RBot.GL
SymantecW32.IRCBot
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DG
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Dropper-12487
KasperskyTrojan.Win32.Buzus.sbac
AlibabaTrojanDropper:Win32/Buzus.03df4b8d
NANO-AntivirusTrojan.Win32.Bifrose.itjj
ViRobotBackdoor.Win32.A.IRCBot.5632.B
RisingBackdoor.Win32.SdBot.flj (CLASSIC)
SophosMal/Behav-103
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Inject.3826
ZillyaTrojan.Buzus.Win32.131332
TrendMicroTROJ_FAM_00014a7.TOMA
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Dropper.SIS (B)
IkarusTrojan.Crypt
JiangminBackdoor/SdBot.frt
WebrootVir.Tool.Gen
VaristW32/Risk.TWWP-8494
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Buzus
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDropper:Win32/Dooxud.A
XcitiumBackdoor.Win32.SdBot.~FV@njznt
ArcabitTrojan.Dropper.SIS
ZoneAlarmTrojan.Win32.Buzus.sbac
GDataTrojan.Dropper.SIS
GoogleDetected
AhnLab-V3Dropper/Win32.Agent.C46995
McAfeeGenericRXCO-ZV!5FF9C89933A6
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
VBA32SScope.TrojanInjector.MY
Cylanceunsafe
PandaW32/Oscarbot.UH.worm
TrendMicro-HouseCallTROJ_FAM_00014a7.TOMA
TencentMalware.Win32.Gencirc.114c6c9d
YandexTrojan.GenAsa!+AftErs+svI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.777970.susgen
FortinetW32/Injector.SD!tr
AVGWin32:BackDoor-ACA [Trj]
AvastWin32:BackDoor-ACA [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1951612991?

Malware.AI.1951612991 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment