Malware

Malware.AI.2089732867 removal

Malware Removal

The Malware.AI.2089732867 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2089732867 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.2089732867?


File Info:

name: BA92D67E4DF4CCEA3116.mlw
path: /opt/CAPEv2/storage/binaries/5b9f92f949a9ffa918ef0994f89735edd95386608562fd64ec8ce23a205c4429
crc32: A673DC93
md5: ba92d67e4df4ccea3116df567c650fe2
sha1: f42db1053bc1999af58a1211b7a3ce1d57b26a6a
sha256: 5b9f92f949a9ffa918ef0994f89735edd95386608562fd64ec8ce23a205c4429
sha512: 6e1606d63bc48d94c366e9c425090c38c3b17ef55ff9ff7a8d2bbbe091d4eebac594c69d328bdf552c0ee7741dd0f9a9df5efde47cc42f5d1ed0f3435d09b669
ssdeep: 6144:SU+iUDHaNJCYLzgSedoYIlvmIB7CSt3IJSlEqyRKKO7JfbmULoSF:SUnUGJlgSqzlSt31vy9YNoSF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1955423436D499284DA7F13F87C3EAED41C30E8456A52EEE9147422FF763AAC597A0730
sha3_384: 21d3ad717851e4fd7de1337383975a0fac5720232e62396e218d19d082343cbf7314eba2bd36879aebd61f78b25c325b
ep_bytes: 60be002056008dbe00f0e9ff5789e58d
timestamp: 2011-02-27 17:24:31

Version Info:

Translation: 0x0409 0x04b0
Comments: ZMRPSFHAV
CompanyName: ICVTGGJCL
FileDescription: FYXEPEIQL
ProductName: KUSWRKZBD
FileVersion: 30.05.0021
ProductVersion: 30.05.0021
InternalName: qnubtwq
OriginalFilename: qnubtwq.exe

Malware.AI.2089732867 also known as:

LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47612799
FireEyeGeneric.mg.ba92d67e4df4ccea
CAT-QuickHealTrojan.Agent
ALYacTrojan.GenericKD.47612799
CylanceUnsafe
SangforTrojan.Win32.Agent.qwfsom
K7AntiVirusTrojan ( 0021a0b51 )
AlibabaTrojan:Win32/Injector.22a730b8
K7GWTrojan ( 0021a0b51 )
Cybereasonmalicious.e4df4c
CyrenW32/Trojan.EBYH-1587
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EYU
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agent.qwfsom
BitDefenderTrojan.GenericKD.47612799
NANO-AntivirusTrojan.Win32.MQI.ecfnhm
SUPERAntiSpywareTrojan.Agent/Gen-Injector[Variant]
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11daa515
Ad-AwareTrojan.GenericKD.47612799
EmsisoftTrojan.GenericKD.47612799 (B)
ComodoTrojWare.Win32.VBKrypt.cjb@4vg4ed
DrWebTrojan.MulDrop6.43306
ZillyaTrojan.Injector.Win32.527024
TrendMicroTROJ_GEN.R002C0RL421
McAfee-GW-EditionBehavesLike.Win32.PWSSpyeye.dc
SophosMal/Generic-S + Troj/EyeStye-F
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.47612799
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1867F0D
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Injector.286723.A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.VBKrypt.R456408
McAfeeRDN/Generic Dropper
MAXmalware (ai score=88)
VBA32SScope.Trojan.VBRA.6747
MalwarebytesMalware.AI.2089732867
TrendMicro-HouseCallTROJ_GEN.R002C0RL421
RisingTrojan.Injector!1.A764 (CLOUD)
YandexTrojan.Injector!DpFryf2O+9U
IkarusTrojan-Dropper.Win32.VB
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.MQI!tr
BitDefenderThetaAI:Packer.101DB00320
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.2089732867?

Malware.AI.2089732867 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment