Malware

Malware.AI.2021949504 removal

Malware Removal

The Malware.AI.2021949504 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2021949504 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2021949504?


File Info:

name: 6BA4B79CF92632BD147A.mlw
path: /opt/CAPEv2/storage/binaries/8faae91de9078621e48142b9b6f5b6f8e99de2bd63faeb85bc1b43c40de64e15
crc32: A6B59BA2
md5: 6ba4b79cf92632bd147ac55f3e70d1c2
sha1: 469c011638b4e82b42d35d05f1d05b9661e857c5
sha256: 8faae91de9078621e48142b9b6f5b6f8e99de2bd63faeb85bc1b43c40de64e15
sha512: c476732cb71e481e40606de43a9ea10ed92a77362423636e9b152dd883df4161696969e56330c058d8bc459eb4cc70ed2a439423326d08ddd42ae1f4475137ba
ssdeep: 49152:7Gv7EwysLszMYzHE9XPiQtQ6fr+R5hPtXxAJzhzFzSLDU3/FNIXzWqYWXg62:7MUsY9kVNcfh32Jz/3/FF62
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3E5337190C2EF9BE011A079D669A3FCEB5B8C96D041047B7FC9BC3DBA7A421D844369
sha3_384: a194f5735ef224a623ab92b80c2d4533e71af8bce40697f414ab0968788e888f274a689eccf733d7b8717799aa90051a
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Drason Studio
FileDescription: PxeTool
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments: QQ:241502159
Translation: 0x0804 0x03a8

Malware.AI.2021949504 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Doina.17060
FireEyeGen:Variant.Doina.17060
McAfeeArtemis!6BA4B79CF926
Cylanceunsafe
VIPREGen:Variant.Doina.17060
SangforTrojan.Win32.Tftpd.V5gc
K7AntiVirusUnwanted-Program ( 004bdb2e1 )
K7GWUnwanted-Program ( 004bdb2e1 )
CrowdStrikewin/malicious_confidence_60% (D)
ArcabitTrojan.Doina.D42A4
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TFTPD32.B potentially unsafe
APEXMalicious
BitDefenderGen:Variant.Doina.17060
NANO-AntivirusTrojan.Win32.RiskGen.badqhe
AvastWin32:Malware-gen
EmsisoftGen:Variant.Doina.17060 (B)
DrWebProgram.WebRemote.393
ZillyaTrojan.BestaFera.Win32.634
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
SophosGeneric Reputation PUA (PUA)
IkarusBackdoor.Win32
Antiy-AVLRiskWare/Win32.TFTPD32
Kingsoftmalware.kb.a.994
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Doina.17060
GoogleDetected
ALYacGen:Variant.Doina.17060
MAXmalware (ai score=81)
VBA32TrojanDownloader.Dakedam
MalwarebytesMalware.AI.2021949504
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H09IK23
RisingMalware.Strealer!8.1EF (CLOUD)
YandexTrojan.GenAsa!eYANNRcAvvE
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/TFTPD32
AVGWin32:Malware-gen
Cybereasonmalicious.638b4e
DeepInstinctMALICIOUS

How to remove Malware.AI.2021949504?

Malware.AI.2021949504 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment