Malware

Malware.AI.196696947 removal instruction

Malware Removal

The Malware.AI.196696947 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.196696947 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.196696947?


File Info:

name: 0F8F63E28B7816B3CD62.mlw
path: /opt/CAPEv2/storage/binaries/736534fc4a2d5672aa6a23a4a4db195473b64c0bebcb20bd5ebe5bfa9809cd7a
crc32: 785F88D0
md5: 0f8f63e28b7816b3cd62716d8ce4c178
sha1: c68bfcb42574936fd9ce748c887808820a5f8c44
sha256: 736534fc4a2d5672aa6a23a4a4db195473b64c0bebcb20bd5ebe5bfa9809cd7a
sha512: 832129e954d24c9f55b3793612fa6855203913facca66dc93dad1cfe9cf55d4bcc20849b78749225fe0b9cfec3f589702084fd740fc8e6a00e2aef82383c9707
ssdeep: 24576:n3ub5cDzp/Ook9bVHIKAuTVijaUH2AcQNoMJ+CeWwIpA1JeuoSOBRcSrBIMmCpCp:157cQKauDOTcSrqMmpnF8OMJLjOlXl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE060612B244663ADE5F1B36F5238150B937AED3E7929C5B06E07C08FE76B40367E606
sha3_384: 56773d321435d8535869aaadb890f378a93fb961f924f445807d2a9b01e93d66df67f38e1fad1f3ea7e9957f85dd7ab3
ep_bytes: 558bec83c4f0b8dc6f6200e8fc04deff
timestamp: 2020-04-22 21:21:05

Version Info:

FileVersion: 2.0.0.0
ProductVersion: 1.0.0.0
ProgramID: com.embarcadero.EaseUS_DRW
FileDescription: EaseUS_DRW
ProductName: EaseUS_DRW
Translation: 0x0409 0x04e4

Malware.AI.196696947 also known as:

LionicRiskware.Win32.Bulz.1!c
MicroWorld-eScanGen:Variant.Bulz.446580
FireEyeGen:Variant.Bulz.446580
McAfeeGenericRXAA-FA!0F8F63E28B78
CylanceUnsafe
ZillyaTrojan.Keygen.Win32.4456
SangforSuspicious.Win32.Bulz.446580
K7AntiVirusUnwanted-Program ( 0056d3091 )
K7GWUnwanted-Program ( 0056d3091 )
BitDefenderThetaAI:Packer.5C6BE60E19
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Keygen.AOO potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002H09KN21
BitDefenderGen:Variant.Bulz.446580
AvastFileRepMalware
Ad-AwareGen:Variant.Bulz.446580
EmsisoftGen:Variant.Bulz.446580 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.wm
SophosGeneric PUA MG (PUA)
GDataGen:Variant.Bulz.446580
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3PUP/Win32.DealPly.C3457378
ALYacGen:Variant.Bulz.446580
MAXmalware (ai score=81)
MalwarebytesMalware.AI.196696947
APEXMalicious
RisingTrojan.Generic@ML.82 (RDML:R99FRDWRDnEmqf2b9xfyyA)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/KeyGen
AVGFileRepMalware

How to remove Malware.AI.196696947?

Malware.AI.196696947 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment