Malware

What is “Malware.AI.2516832750”?

Malware Removal

The Malware.AI.2516832750 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2516832750 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2516832750?


File Info:

name: BB6AC26E2B208AF26755.mlw
path: /opt/CAPEv2/storage/binaries/716270618fed82803de089e673dea2bca865cb1dc629fc7a5f37545ce8f44368
crc32: E32CC29D
md5: bb6ac26e2b208af26755eecb22533239
sha1: aa7996f09774b8630c9f4bdec9c6b3f4e6e75ded
sha256: 716270618fed82803de089e673dea2bca865cb1dc629fc7a5f37545ce8f44368
sha512: 7277fc1ea265672f288178ebf29e9f8682130cd9e7e577ef6034dbb5fdc66fe2ec75dc94e9b4189d557febdbfa812a01bf7480a907413e11864a955612e28b94
ssdeep: 1536:6Zssqoq5OZ6hpAp/B1JE/QCCZ/zhaSFoZtPWb:qsH5OZ6hpS1JE/QCu/zhnFAub
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18E73F2AA3F86172FD5420D3838530B0967F87A6854D79BC30514CCEE3D9081F6D9ABA6
sha3_384: c0bb5372895989cf991a2d007cf6cb21d27b82de3ee1c1c7be1de0cddfde91fd135bd1a48be4bfefab1cc0e68e6fe6ff
ep_bytes: 60be000043008dbe0010fdff5783cdff
timestamp: 2012-04-26 10:24:52

Version Info:

FileVersion: 2.1.1.2
FileDescription: P2P加速器
ProductName: P2P加速器
ProductVersion: 2.1.1.2
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: Acc影视加速器
Translation: 0x0804 0x04b0

Malware.AI.2516832750 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Strictor.282813
FireEyeGeneric.mg.bb6ac26e2b208af2
SkyhighGenericRXFB-PK!D2EA737FF646
McAfeeGenericRXFB-PK!D2EA737FF646
MalwarebytesMalware.AI.2516832750
VIPREGen:Variant.Strictor.282813
SangforSuspicious.Win32.Save.a
BitDefenderGen:Variant.Strictor.282813
CrowdStrikewin/malicious_confidence_60% (D)
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.BlackMoon.D suspicious
CynetMalicious (score: 100)
APEXMalicious
NANO-AntivirusTrojan.Win32.FakeAlert.kbcrhw
RisingMalware.Undefined!8.C (TFE:5:aQNnSqUO9jV)
EmsisoftGen:Variant.Strictor.282813 (B)
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
VaristW32/Blackmoon.CM.gen!Eldorado
Antiy-AVLTrojan[Banker]/Win32.BlackMoon.a
Kingsoftmalware.kb.b.886
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Strictor.D450BD
GDataWin32.Trojan-Stealer.BlackMoon.D
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36792.emKfaK4mCHcj
ALYacGen:Variant.Strictor.282813
MAXmalware (ai score=85)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Occamy
Cylanceunsafe
IkarusPUA.BlackMoon
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.WP!tr
AVGWin32:WrongInf-G [Susp]
Cybereasonmalicious.09774b
AvastWin32:WrongInf-G [Susp]

How to remove Malware.AI.2516832750?

Malware.AI.2516832750 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment