Malware

Should I remove “Malware.AI.2191639820”?

Malware Removal

The Malware.AI.2191639820 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2191639820 virus can do?

  • At least one process apparently crashed during execution
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Creates a hidden or system file
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.2191639820?


File Info:

name: 19902FC565161BF7C305.mlw
path: /opt/CAPEv2/storage/binaries/6c9118ff36a711d7d8a2dfd344eaa2b51b4c67706fc03dc521018916c154522c
crc32: B56DB2B1
md5: 19902fc565161bf7c3055bd472bf68c0
sha1: 016a9c16c3562f04774cbbb7172a064c7a98bf42
sha256: 6c9118ff36a711d7d8a2dfd344eaa2b51b4c67706fc03dc521018916c154522c
sha512: d9c6e789252ef774d4b9c9ae4db0a94a1e84a33fdba9cb635da3f1a6741eb53ffa24aa0f7f0cdac9f39d78ab60c982ef58634137489084fdb7c1f324096785a9
ssdeep: 1536:5uU2V1gxOTewwX96qg8x+I854j4r8GkGrwzRyRJHVpRdOgo+rJ6qz+mDiwPnY:5u7gxOC6vIy4cPwcRVzE+1hHY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FDC3E023A8A5C136F84084F04D7C2AB3BB7F7E50026A617F43C5E9558FF0164ED0AA6B
sha3_384: 752699adffe190f76055e38b385618896893d81a964193a7ae4ced1a41cecf4955c7b535b51e9e1be2f27ff78017b81d
ep_bytes: eb1066623a432b2b484f4f4b90e91c91
timestamp: 2012-08-08 12:50:36

Version Info:

0: [No Data]

Malware.AI.2191639820 also known as:

LionicTrojan.Win32.Generic.lCsq
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.KDV.692967
FireEyeGeneric.mg.19902fc565161bf7
ALYacTrojan.Generic.KDV.692967
CylanceUnsafe
ZillyaWorm.Dorkbot.Win32.4419
SangforTrojan.Win32.Agent.updb
K7AntiVirusRiskware ( 0015e4f01 )
K7GWRiskware ( 0015e4f01 )
Cybereasonmalicious.565161
VirITTrojan.Win32.Generic.LOH
CyrenW32/Dorkbot.TWKG-8975
SymantecTrojan.Ransomlock!g8
ESET-NOD32Win32/Dorkbot.B
APEXMalicious
ClamAVWin.Trojan.Dorkbot-522
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.KDV.692967
NANO-AntivirusTrojan.Win32.Carberp.cchflh
ViRobotTrojan.Win32.A.Gimemo.74240.D
AvastWin32:Cryptor
TencentWin32.Worm.Dorkbot.Dztw
SophosML/PE-A + Mal/EncPk-AGD
ComodoMalware@#118qaq0xz6lud
F-SecureWorm.WORM/Dorkbot.A.2302
DrWebBackDoor.IRC.NgrBot.13
VIPRETrojan.Win32.Reveton.a (v)
TrendMicroTROJ_SPNR.02HJ12
McAfee-GW-EditionBehavesLike.Win32.Sytro.ch
EmsisoftTrojan.Generic.KDV.692967 (B)
IkarusTrojan.Win32.Tobfy
JiangminTrojan/Buzus.bgnf
AviraWORM/Dorkbot.A.2302
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Nrgbot
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/DorkBot.DU
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Generic.KDV.692967
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Jorik.R39538
McAfeeArtemis!19902FC56516
VBA32BScope.Malware-Cryptor.Oop
MalwarebytesMalware.AI.2191639820
TrendMicro-HouseCallTROJ_SPNR.02HJ12
RisingWorm.Dorkbot!8.1B4 (RDMK:cmRtazr+l5uLTNcYeM4k0dsL+fxI)
YandexTrojan.GenAsa!pdAaq9cIcIw
MaxSecureTrojan.Spy.Win32.Zbot.fmki
FortinetW32/Kryptik.4C06!tr
BitDefenderThetaGen:NN.ZexaF.34182.hGY@aO3OHgk
AVGWin32:Cryptor
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.2191639820?

Malware.AI.2191639820 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment