Malware

Malware.AI.1956969040 removal tips

Malware Removal

The Malware.AI.1956969040 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1956969040 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1956969040?


File Info:

name: 700FC31E56923701E13C.mlw
path: /opt/CAPEv2/storage/binaries/196e79962696b65959fb69d1b035bd657a54ae12daa967bf8cd7c1475adb2cb6
crc32: 29966510
md5: 700fc31e56923701e13c1ffac7452f78
sha1: 6648607ca30235d6e86a16e7f4e120351571dc4a
sha256: 196e79962696b65959fb69d1b035bd657a54ae12daa967bf8cd7c1475adb2cb6
sha512: 5b51a11a84d51b80417475e05fa6d12014f86e41957321fec8c12bfb9a35f63ed5d8f7686788b3385eeea3e99d73c649a0979d89f5ac071a11691223c8890559
ssdeep: 3072:7Ort2CFaSevj6JtoyY4gDNzFa6gTxcyyt8vw70cof5Q5lWJNn:ct2CFevj60yWDNzFjgTxcyytgw70cofR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18D046C31ABC580F2DA1620B014FD67707BFCA9876F281ADB9F78DF6898170E1B436195
sha3_384: c63ba80de56be2f60cdcc8bc5cd177ffb7f83c699dec5a3237c6803110032e336543a11931e41de0f726c8b7bb8080ab
ep_bytes: 558bec6aff68f822420068aaf8410064
timestamp: 2007-09-11 08:48:50

Version Info:

Comments:
CompanyName: OEM
FileDescription: ngslotd
FileVersion: 1, 2, 7, 911
InternalName: ngslotd
LegalCopyright: Copyright (C) 2004-2006 OEM
LegalTrademarks:
OriginalFilename: ngslotd.exe
PrivateBuild:
ProductName: ngslotd
ProductVersion: 1, 0, 0, 0
SpecialBuild:
Translation: 0x0804 0x04b0

Malware.AI.1956969040 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
SkyhighBehavesLike.Win32.Rootkit.ch
Cylanceunsafe
SangforTrojan.Win32.Agent.Vnlv
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/dUmPeX.f5da274e
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_60% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Evo-gen [Trj]
F-SecureTrojan.TR/Crypt.ULPM.Gen
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.SGeneric
KingsoftWin32.Troj.Unknown.a
XcitiumPacked.Win32.MUPX.Gen@24tbus
GoogleDetected
McAfeeArtemis!700FC31E5692
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.1956969040
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.ca3023
DeepInstinctMALICIOUS

How to remove Malware.AI.1956969040?

Malware.AI.1956969040 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment