Malware

Malware.AI.1971589450 removal tips

Malware Removal

The Malware.AI.1971589450 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1971589450 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.1971589450?


File Info:

name: C23B77080168C24EA85F.mlw
path: /opt/CAPEv2/storage/binaries/a73f6cb3bbdfc25004c8580ce28f5bb1945d1bbb40c30fab35752124b9ddf165
crc32: FA282B08
md5: c23b77080168c24ea85f8c3791b5a07e
sha1: 58a42c554c3a647306d5cf6caaa7c3d78c835d07
sha256: a73f6cb3bbdfc25004c8580ce28f5bb1945d1bbb40c30fab35752124b9ddf165
sha512: 577621b92784c144c5cb53eba8c9ced04b8f59c9aea4721a68233293c866c492fa0cf8af0ca37b81b7574dcbcb76872b014b152194ad9c8999e19dbdf660a584
ssdeep: 49152:vN4+SPDSUPKCjxIo5Bps8D+Unvoxz1on+:WHVxR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19DB51800A700912DD8BB66F90FAD712DA11CEEE15754A1CB91C86AFECF796F03D3419A
sha3_384: ca614af5e8e4d93cd6c92f3da53c13e07e847571c6b7a4fc67d7439db8569e7a423c5e8fc448bbb359cb1ccd7a237867
ep_bytes: e940391400e9bb570a00e9762f0600e9
timestamp: 2011-04-12 00:36:47

Version Info:

Comments: 如有针打软硬件设计需求 请EMAIL:hanqiu007@126.com
CompanyName: 开心
FileDescription: 打印针测试程序
FileVersion: 1.0.0.1
InternalName: 24针测试程序.exe
LegalCopyright: TODO: (C)开心留所有权利。
OriginalFilename: 24针测试程序.exe
ProductName: 针测试程序
ProductVersion: 1.0.0.1
Translation: 0x0804 0x03a8

Malware.AI.1971589450 also known as:

DrWebBackDoor.Darkshell.418
MicroWorld-eScanTrojan.Downloader.JQJR
FireEyeTrojan.Downloader.JQJR
CAT-QuickHealW32.Otwyacal.C
ALYacTrojan.Downloader.JQJR
BitDefenderThetaGen:NN.ZexaF.34786.yI3@aeK598dj
CyrenW32/Trojan.WQGK-7655
SymantecW32.Wapomi.C!inf
Elasticmalicious (high confidence)
ESET-NOD32Win32/Wapomi.BA
TrendMicro-HouseCallMal_DLDER
ClamAVWin.Trojan.Downloader-62876
KasperskyTrojan-Downloader.Win32.Small.cwzz
BitDefenderTrojan.Downloader.JQJR
NANO-AntivirusTrojan.Win32.Small.cqkcra
AvastWin32:Malware-gen
RisingVirus.Wapomi!8.55 (CLOUD)
Ad-AwareTrojan.Downloader.JQJR
EmsisoftTrojan.Downloader.JQJR (B)
VIPRETrojan.Downloader.JQJR
TrendMicroMal_DLDER
McAfee-GW-EditionBehavesLike.Win32.BadFile.vm
SophosMal/Generic-R
IkarusExploit.Win32.ShellCode
GDataTrojan.Downloader.JQJR (2x)
AviraHEUR/AGEN.1231522
MAXmalware (ai score=81)
ZoneAlarmVirus.Win32.Otwycal.a
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!C23B77080168
MalwarebytesMalware.AI.1971589450
TencentVirus.Win32.Wapomi.a
YandexTrojan.DL.Small!oRzPgJ5EbEc
MaxSecureVirus.W32.Otwycal.A
FortinetW32/Wapomi.AO
AVGWin32:Malware-gen
Cybereasonmalicious.80168c
PandaTrj/CI.A

How to remove Malware.AI.1971589450?

Malware.AI.1971589450 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment