Malware

Malware.AI.1954770338 removal

Malware Removal

The Malware.AI.1954770338 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1954770338 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1954770338?


File Info:

name: 4B25DA47E19E3A2ACE0E.mlw
path: /opt/CAPEv2/storage/binaries/18aca4a0e506968de75883ba3ad10da1cffa0b335f4fb5bce0810966a3b46210
crc32: 1533F67A
md5: 4b25da47e19e3a2ace0ec54c9338e4bd
sha1: c118f10f85169ef95d060de14c620c71fe8ef752
sha256: 18aca4a0e506968de75883ba3ad10da1cffa0b335f4fb5bce0810966a3b46210
sha512: 71d8a5f1410fd08f94ee641fc2a1fa650e66a5838d6af2a0e2fb76b33dde02686ba57b6778feacb22fc82cbc7ae043de72cc99f4fc5404fcf657ec92c6bf894b
ssdeep: 49152:xe2PJLa+QXLfgH2AZX6R2AZX2LB6qfD9DxpP:xe2PJGFTy2AZe2AZGFZJDxpP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA75F102B7D690B6D8933D7255B3D33AAB3879150726C69BEFD01E23DE214309F263A5
sha3_384: f733cceee53170ad4ef9d9ccd661a329e97617656cdbb7df852c21e4a30dc00a513a95de8ba7e74ae5c5de3e42174581
ep_bytes: e8c4af0000e979feffff8bff558bec8b
timestamp: 2008-12-24 09:00:07

Version Info:

FileVersion: 3, 3, 0, 0
Comments: Den Spike Unattendeds
FileDescription:
LegalCopyright: © Eaglesteam 2014
Translation: 0x0809 0x04b0
CompiledScript: AutoIt v3 Script : 3, 3, 0, 0

Malware.AI.1954770338 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MalwarebytesMalware.AI.1954770338
K7AntiVirusUnwanted-Program ( 004d38111 )
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.f85169
SymantecTrojan.Gen.9
tehtrisGeneric.Malware
ESET-NOD32Win64/HackTool.Crack.CX potentially unsafe
CynetMalicious (score: 100)
APEXMalicious
SophosMal/Generic-R
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.gen
Antiy-AVLTrojan/Win32.BTSGeneric
Kingsoftmalware.kb.a.955
MicrosoftTrojan:Win32/Agent
GDataWin32.Trojan.Agent.WZ82U1
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BH01LS23
MaxSecureWorm.Win32.AutoIt.QN
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_90% (W)

How to remove Malware.AI.1954770338?

Malware.AI.1954770338 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment