Malware

Should I remove “Malware.AI.240101750”?

Malware Removal

The Malware.AI.240101750 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.240101750 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.240101750?


File Info:

name: C417A3E9AEC9572F39DE.mlw
path: /opt/CAPEv2/storage/binaries/b6a0de736dfb890dbadb14282365d895e09b59370d6f6e2db0b797155871d403
crc32: 4AA22550
md5: c417a3e9aec9572f39debb24d72761df
sha1: 0d9da350bd9fa7f1e27cd260562cbdacebcdf7a7
sha256: b6a0de736dfb890dbadb14282365d895e09b59370d6f6e2db0b797155871d403
sha512: 734be7a61663f0c63a548f209edbe097d3450600bca9130e3558f852bc411f91f56061f6a030f81923d1b27b212ed93ddd746544def59a0c8522ba24a850809b
ssdeep: 768:T9kJ0iH3qB+lcXhWn+Tg0O98uMYLu/PZ4FbE9IOTy8EMjtZ+v2BxPha5:T9knHnghW+FoZLx6Ir8EMXF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142135A53D24411BAC6D243317E16BF6747747E2B953E831DAE6C348ABF34BE18E15A20
sha3_384: 900c074fa9d38843a63b1afe9203a7f344fa155307ff77e60f4708d3d04bc6c7ec2d4854e11a931410722093b0a1cbbb
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1972-12-25 05:33:23

Version Info:

FileVersion: 11.2.2014.1718
FileDescription: 一键GHOST硬盘版卸载辅助程序
ProductName: 一键GHOST硬盘版
ProductVersion: 11.2.2014.1718
CompanyName: DOS之家
LegalCopyright: DOS之家 http://doshome.com 葛明阳
Comments: 1KEY GHOST HD v2014.07.18
Translation: 0x0804 0x04b0

Malware.AI.240101750 also known as:

LionicVirus.Win32.Nimnul.lhYK
tehtrisGeneric.Malware
FireEyeGeneric.mg.c417a3e9aec9572f
CylanceUnsafe
SangforPUP.Win32.Presenoker.uljrg
Cybereasonmalicious.0bd9fa
VirITTrojan.Win32.Click2.CLPR
CyrenW32/S-1a931a93!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.OnlineGames-1924
NANO-AntivirusTrojan.Win32.Clicker.descls
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
SophosMal/Generic-S (PUA)
DrWebTrojan.Click2.42995
McAfee-GW-EditionBehavesLike.Win32.Trojan.ph
Trapminemalicious.high.ml.score
GDataWin32.Riskware.FlyStudio.C
WebrootW32.Malware.Gen
Antiy-AVLTrojan/Generic.ASMalwS.330C
ViRobotBackdoor.Win32.Hupigon.50222
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
McAfeeGenericRXAA-AA!C417A3E9AEC9
VBA32Trojan.KillFiles
MalwarebytesMalware.AI.240101750
RisingTrojan.Wacatac!8.10C01 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FlyStudio.C!tr

How to remove Malware.AI.240101750?

Malware.AI.240101750 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment