Malware

Malware.AI.2021604561 removal guide

Malware Removal

The Malware.AI.2021604561 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2021604561 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.2021604561?


File Info:

name: BAA77C2F564346AB61C7.mlw
path: /opt/CAPEv2/storage/binaries/8b1cf60da1a4921e9c16c165ece86529f458ad61a12f2ed76a4609132555824c
crc32: B0831BE8
md5: baa77c2f564346ab61c71a9249788c01
sha1: 4d6caaef7818c4404af85d9238933f645f4f3d22
sha256: 8b1cf60da1a4921e9c16c165ece86529f458ad61a12f2ed76a4609132555824c
sha512: a002459cfc221651d322b9072936f8d22d5f8348ed5875609484c6dbdabcac2ccebccc2a7f3db94fa44590c61d9160355bdfd518f30a087ffb503a049d0f06a8
ssdeep: 49152:fM+xyF6uSjvX1wnZ+rAqC9B6IIsIIIIGqmx4w3d8YamTEo6glcv6FB9bRs+zI+zM:zRVdx4w8Od+SFBpR8xU8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BDE5AF12B689893BD0621F76983FC5916835BE702A1688176BF0FE4C2FB97806D35773
sha3_384: 8183461969909f69fe0b475323b28e15c5b195608f913dc7ef25b47b7bc447fe654b92d7cc5c2d07977a66c7ec3a8217
ep_bytes: eb1066623a432b2b484f4f4b90e9ac90
timestamp: 2023-06-27 15:52:57

Version Info:

CompanyName: 深圳市常青藤软件科技有限公司
FileDescription: 小智TODO
FileVersion: 3.2.1.12
InternalName: XZToDo.exe
LegalCopyright: Copyright (C) 2020 深圳市常青藤软件科技有限公司。保留所有权利。
OriginalFilename: XZToDo.exe
ProductName: 小智TODO
ProductVersion: 3.2.1.12
Translation: 0x0804 0x04b0

Malware.AI.2021604561 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.464123
SkyhighBehavesLike.Win32.Generic.vc
McAfeeArtemis!BAA77C2F5643
MalwarebytesMalware.AI.2021604561
ZillyaTrojan.Agent.Win32.3572003
K7AntiVirusPassword-Stealer ( 0059b7251 )
K7GWPassword-Stealer ( 0059b7251 )
Cybereasonmalicious.f7818c
ArcabitTrojan.Fragtor.D714FB
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Agent.OPS
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.QQPass.gen
BitDefenderGen:Variant.Fragtor.464123
NANO-AntivirusTrojan.Win32.QQPass.jyfvan
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.10bf545a
F-SecureTrojan.TR/PSW.Agent.pduan
DrWebTrojan.Fakealert.60554
VIPREGen:Variant.Fragtor.464123
FireEyeGeneric.mg.baa77c2f564346ab
EmsisoftGen:Variant.Fragtor.464123 (B)
JiangminTrojan.PSW.QQPass.bem
AviraTR/PSW.Agent.pduan
Antiy-AVLGrayWare/Win32.Wacapew
ZoneAlarmHEUR:Trojan-PSW.Win32.QQPass.gen
GDataGen:Variant.Fragtor.464123
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5481245
ALYacGen:Variant.Fragtor.464123
MAXmalware (ai score=80)
Cylanceunsafe
RisingStealer.Agent!1.E64F (CLASSIC)
IkarusTrojan.Win32.Agent
AVGWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.2021604561?

Malware.AI.2021604561 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment