Malware

How to remove “Malware.AI.1971558260”?

Malware Removal

The Malware.AI.1971558260 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1971558260 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1971558260?


File Info:

name: 35CAAE29C47DFB570773.mlw
path: /opt/CAPEv2/storage/binaries/6395c4a8495d3bff293a8a55ca3c5ebf68a616ee212b2a7284610b0a3f7bb5d4
crc32: 2120FBE7
md5: 35caae29c47dfb570773f6d5fd37e625
sha1: 6519a71c64aa216673f3582da1338e22c4ad78a8
sha256: 6395c4a8495d3bff293a8a55ca3c5ebf68a616ee212b2a7284610b0a3f7bb5d4
sha512: b71cd363e681795960c88b3ecb0bb54e52b1ce02c4e2a529e2f7985c7fa827a6640ced1019ac6998e22a6ea9c996566af63d857b41692992f7c87d8c9bef0440
ssdeep: 1536:BgxogY1mXG1uK9J8XABLORol4L35/0o+MfAubri9LAO4/Udof:qCKUJ8XABLJl4L33Ab9kJ/Ud
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C736B22B4E4C072E06715B19D68ABA7066FBC604B7545C7F7890BBB2E611D04E393AF
sha3_384: 9532169e95ed0284f44d281af1a073a972e18e9b53b5d112b96c94d0ca4ea94cc316ef59a9b98d44084f775abf08fe46
ep_bytes: e836240000e989feffff8bff558bec83
timestamp: 2020-01-22 18:15:48

Version Info:

0: [No Data]

Malware.AI.1971558260 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agentb.4!c
DrWebTrojan.Siggen14.20542
MicroWorld-eScanGen:Variant.Adware.ConvertAd.16
McAfeePUP-XPM-ZW
MalwarebytesMalware.AI.1971558260
VIPREGen:Variant.Adware.ConvertAd.16
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Generic.7f1a0e8a
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Adware.ConvertAd.16
BitDefenderThetaGen:NN.ZexaE.36662.eqW@aCjSP2p
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Speccom.AB
APEXMalicious
KasperskyHEUR:Trojan.Win32.Agentb.gen
BitDefenderGen:Variant.Adware.ConvertAd.16
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.117d9b4f
EmsisoftGen:Variant.Adware.ConvertAd.16 (B)
F-SecureAdware.ADWARE/ConvertAd.zfxjv
ZillyaTrojan.Agent.Win32.2036732
TrendMicroTROJ_GEN.R002C0WE221
McAfee-GW-EditionPUP-XPM-ZW
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.35caae29c47dfb57
SophosGeneric Reputation PUA (PUA)
IkarusTrojan-Downloader.Win32.Speccom
JiangminTrojan.Agentb.lyx
WebrootW32.Adware.Gen
GoogleDetected
AviraADWARE/ConvertAd.zfxjv
Antiy-AVLTrojan[APT]/Win32.Indigozebra
MicrosoftTrojan:Win32/Skeeyah.A
ViRobotBackdoor.Win32.S.Agent.77824.CK
ZoneAlarmHEUR:Trojan.Win32.Agentb.gen
GDataGen:Variant.Adware.ConvertAd.16
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.ConvertAd.C4447150
VBA32BScope.Trojan.Agent
ALYacBackdoor.Agent.BoxCaon
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WE221
RisingDownloader.Speccom!8.ECD (TFE:5:nMul43f2BEV)
YandexTrojan.Agentb!fVN2ySRKqzo
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.9325066.susgen
FortinetRiskware/Agentb
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1971558260?

Malware.AI.1971558260 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment