Malware

Malware.AI.2096849201 removal instruction

Malware Removal

The Malware.AI.2096849201 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2096849201 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.2096849201?


File Info:

name: A9040FA27D5BFDEF9C54.mlw
path: /opt/CAPEv2/storage/binaries/d10eded81b13a7d2601f08334364257d1b257da3f2e231543e326a547e071ba5
crc32: 8D236A08
md5: a9040fa27d5bfdef9c545154a7e3542a
sha1: f8eafda56edafd6a7d9d404bdb695f5afda8f770
sha256: d10eded81b13a7d2601f08334364257d1b257da3f2e231543e326a547e071ba5
sha512: 73c2e67fe014af27c5f2d04d86f119e15e12faa34010147178f2996eb45239b07d90c336644d1438dea75e5bf3656ca631c9dbbe2fb4a98c560e940ccb3d26d4
ssdeep: 49152:CwCaUqm1iMmVfR4Zbn9LqT1yO+yTMaP+9+:CwCam1iMm9R419LqBzo5+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130B5AF22BA818072EA930170967AA77F4939AF30133885C7D3D43D6D5D742D1AB3E79B
sha3_384: b8030a0056528231c18a09bccb8a2ad793c824a7077f058f496f7da5e90f18bb77535d13c5473e818bca4cb0c69ae40f
ep_bytes: e8370e0000e98efeffffff2510075b00
timestamp: 2021-09-02 06:42:05

Version Info:

CompanyName: Shanghai Ziwei Network Technology Co., Ltd.
FileDescription: mininews
FileVersion: 1.0.0.1
InternalName: news.exe
LegalCopyright: Copyright (C) 2020 Ziwei Yingshuang Network Technology Co., Ltd.
OriginalFilename: news.exe
ProductName: easypdf reader
ProductVersion: 1.0.0.1
Translation: 0x0804 0x04b0

Malware.AI.2096849201 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adware.Jaik.47764
FireEyeGeneric.mg.a9040fa27d5bfdef
CAT-QuickHealPUA.SwiminenRI.S21060946
McAfeeGenericRXAA-AA!A9040FA27D5B
ZillyaAdware.ComponentBased.Win32.285
CrowdStrikewin/grayware_confidence_60% (W)
K7GWTrojan-Downloader ( 00588d7a1 )
K7AntiVirusTrojan-Downloader ( 00588d7a1 )
CyrenW32/Adload.FD.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDownloader.Adload.NUS
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.ComponentBased.gen
BitDefenderGen:Variant.Adware.Jaik.47764
TencentMalware.Win32.Gencirc.10cf0418
Ad-AwareGen:Variant.Adware.Jaik.47764
EmsisoftGen:Variant.Adware.Jaik.47764 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.vh
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Adware.Jaik.47764
JiangminAdWare.ComponentBased.eq
Antiy-AVLTrojan/Generic.ASMalwS.336CE8F
MicrosoftTrojan:Win32/Sabsik!ml
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Agent.C4507661
ALYacGen:Variant.Adware.Jaik.47764
MAXmalware (ai score=65)
VBA32Adware.ComponentBased
MalwarebytesMalware.AI.2096849201
TrendMicro-HouseCallTROJ_GEN.R035C0WAV22
RisingDownloader.Adload!8.D1 (C64:YzY0OqN0/oAfBDQc)
IkarusTrojan-Downloader.Win32.Adload
FortinetW32/Adload.NUS!tr.dldr
PandaTrj/Genetic.gen

How to remove Malware.AI.2096849201?

Malware.AI.2096849201 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment