Malware

Malware.AI.1962205450 (file analysis)

Malware Removal

The Malware.AI.1962205450 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1962205450 virus can do?

  • Dynamic (imported) function loading detected
  • Possible date expiration check, exits too soon after checking local time
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Malware.AI.1962205450?


File Info:

name: 9009E95CC443B0BBDC42.mlw
path: /opt/CAPEv2/storage/binaries/e43ce32bdb677578f913006da58c6733c431dfa8ca7dba8c51c171d55f2631ed
crc32: AAE872F9
md5: 9009e95cc443b0bbdc4224cc2baee7bd
sha1: 6f0c75c0d51022def025a4f36cf11d1c5e5566a6
sha256: e43ce32bdb677578f913006da58c6733c431dfa8ca7dba8c51c171d55f2631ed
sha512: a9091953d10cddfd5a6ddcd2c9b6d5e743eee98ad8d53d8a67c5eb4003688926ce03ca39f08f29927f04eb53846eaab1dc126f6e346a2e6c661bc695fed3239c
ssdeep: 96:ne8rApb938rKRHXe8hoEKLojnLgZqu4gLHXRIlRj0KPWer2PV3dhpaeNt2pzCR1K:1ApfRHubAgZqjcHXRo+y05Mu4o2Z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10122644601ED222FF4FB2FB39BF17AE9C2D7F1A5486A29FC14C019865712C54EA32572
sha3_384: b578ba454d1e3cb3ae729e658501abc5f10c3d716b8539ac1f46344885263b8167fcf4c624d4d4ccd6803245d6385c96
ep_bytes: ff250020400000000000000000000000
timestamp: 1970-01-01 00:00:00

Version Info:

Translation: 0x007f 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 0.0.0.0
InternalName: yunusdns
LegalCopyright:
LegalTrademarks:
OriginalFilename: yunusdns.exe
ProductName:
ProductVersion:

Malware.AI.1962205450 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.InjectNET.5
MicroWorld-eScanGen:Variant.Barys.1826
FireEyeGeneric.mg.9009e95cc443b0bb
CAT-QuickHealTrojan.Bladabindi
ALYacGen:Variant.Barys.1826
K7AntiVirusTrojan ( 0050062e1 )
BitDefenderGen:Variant.Barys.1826
K7GWTrojan ( 0050062e1 )
Cybereasonmalicious.cc443b
BitDefenderThetaGen:NN.ZemsilF.34062.am0@aa64T1k
SymantecBackdoor.Veilev
ESET-NOD32a variant of MSIL/Kryptik.HXX
TrendMicro-HouseCallTROJ_GEN.R002C0CKS21
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/Bladabindi.0412c392
NANO-AntivirusTrojan.Win32.Starter.ewfqjs
ViRobotTrojan.Win32.Z.Barys.10752
Ad-AwareGen:Variant.Barys.1826
EmsisoftGen:Variant.Barys.1826 (B)
TrendMicroTROJ_GEN.R002C0CKS21
McAfee-GW-EditionTrojan-Veil-FOJV!9009E95CC443
SophosMal/Generic-R + ATK/TurtleLd-B
SentinelOneStatic AI – Malicious PE
AviraTR/Rozena.Gen
MAXmalware (ai score=87)
GDataGen:Variant.Barys.1826
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.C3459511
McAfeeTrojan-Veil-FOJV!9009E95CC443
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.1962205450
PandaTrj/CI.A
APEXMalicious
TencentWin32.Trojan.Generic.Honx
YandexTrojan.Agent!B5ifmvvUIRk
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Veliev.H!tr
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1962205450?

Malware.AI.1962205450 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment