Malware

Malware.AI.204903869 malicious file

Malware Removal

The Malware.AI.204903869 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.204903869 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.204903869?


File Info:

name: C776258CDB6A32661059.mlw
path: /opt/CAPEv2/storage/binaries/2e3f2e0d6ccceeb941fd561b508ae4132e58ff1a6597462efec994e37440d61b
crc32: F33226A6
md5: c776258cdb6a326610594a1be864bb93
sha1: ca5f8bf6326e4f0fdcb72a70ea80df9a19285504
sha256: 2e3f2e0d6ccceeb941fd561b508ae4132e58ff1a6597462efec994e37440d61b
sha512: af56af68a1c24f1fa0d6142d44a8dab7909bff18c6e8d722c524c28ddb58d22bf793b03425b1fc73719f68fa4662ffe48a317572ccdbf8927364d05b8f6b0bf4
ssdeep: 196608:eB0jP+BpskElcUu7y/e0KKXUDlGNagRRiatvRI2ZaOy5dl2eBeM1KYf:eB0avD0KHpI9RRiacE4eYFf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159B622449228BD6CC1289F77AFA5B6D3E30E1CB261AD43283495732A0F737957C9522F
sha3_384: 84d7bda4f8de8e5dfe79d7db8553a8aa76d45722a66aa3bc16cb8ab8fd8fdd10fe5d1065c1968f87fc0c7b33cf9d5881
ep_bytes: 9ce81738000083f907c644240478e945
timestamp: 2023-03-05 07:28:13

Version Info:

0: [No Data]

Malware.AI.204903869 also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.Generic.1!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Fragtor.226161
FireEyeGeneric.mg.c776258cdb6a3266
ALYacGen:Variant.Fragtor.226161
MalwarebytesMalware.AI.204903869
VIPREGen:Variant.Fragtor.226161
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004b942f1 )
AlibabaBackdoor:Win32/Poison.dfeab519
K7GWAdware ( 004b942f1 )
Cybereasonmalicious.6326e4
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
KasperskyBackdoor.Win32.Poison.kjjr
BitDefenderGen:Variant.Fragtor.226161
NANO-AntivirusTrojan.Win32.Poison.jvbxzv
EmsisoftGen:Variant.Fragtor.226161 (B)
F-SecureHeuristic.HEUR/AGEN.1338837
BitDefenderThetaGen:NN.ZexaF.36196.@BW@a8DAfakb
ZillyaBackdoor.Poison.Win32.99512
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
SophosMal/Generic-S (PUA)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1338837
MAXmalware (ai score=86)
Antiy-AVLTrojan[Packed]/Win32.VMProtect
ArcabitTrojan.Fragtor.D37371
ZoneAlarmBackdoor.Win32.Poison.kjjr
GDataGen:Variant.Fragtor.226161
AhnLab-V3Packed/Win32.Vmpbad.C136484
McAfeeArtemis!C776258CDB6A
Cylanceunsafe
TencentWin32.Backdoor.Poison.Vwhl
MaxSecureTrojan.Malware.202589630.susgen
FortinetW32/CoinMiner.ELG!tr.pws
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.204903869?

Malware.AI.204903869 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment