Malware

What is “Malware.AI.279066997”?

Malware Removal

The Malware.AI.279066997 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.279066997 virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.279066997?


File Info:

name: BF81D4857A8DD424B58C.mlw
path: /opt/CAPEv2/storage/binaries/007f4adb17d65b2c5ffb2ee3702ebacbd27cf56972bc33a4e6f9dbf1e97d4d92
crc32: 006F7B24
md5: bf81d4857a8dd424b58c9a61124d63b3
sha1: 7758612b2c19b5ab729188a38cc13cb1b147dd56
sha256: 007f4adb17d65b2c5ffb2ee3702ebacbd27cf56972bc33a4e6f9dbf1e97d4d92
sha512: 5719bd02d3d7364b0c90d2f83c02e2ed726b38dc45fca1082d2d2796c6fd226c7c8eac0b9c167ac901af4850d86c9e8f7c9faf7b9eaf07cd02e629126bbd8e47
ssdeep: 98304:2654piMOJlRFSIx5cF9uB5JHtX4LxBgqwzDeeH:n4cJCLxSHe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193067C02F2C700F9DB46667044FBB7356A244BD61A195BC3E36DFE1999725E2B03B02A
sha3_384: fd2b6026c1d1c672f2c560c9c76d0b8a99be888614836a5117793d0d10ff8b60f9a5d9de9aa753edb3f35f101cb836c4
ep_bytes: 558bec6aff68181d77006874b5720064
timestamp: 2006-03-30 07:55:38

Version Info:

Comments:
CompanyName: KO1 Anti
FileDescription: KnightOnline1 Client
FileVersion: 0, 9, 13, 1719
InternalName: KO1anti
LegalCopyright: Copyright ? 2013. KNIGHTONLINE1.COM
LegalTrademarks:
OriginalFilename: KnightOnline.exe
PrivateBuild:
ProductName: Knights OnLine Client
ProductVersion: 2, 3, 11, 1718
SpecialBuild:
Translation: 0x0000 0x04b0

Malware.AI.279066997 also known as:

BkavW32.Common.C3665E43
LionicTrojan.Win32.GenericRXAS.4!c
SkyhighGenericRXAS-UE!BF81D4857A8D
MalwarebytesMalware.AI.279066997
SangforTrojan.Win32.Agent.Vqcs
VirITTrojan.Win32.Agent.ARLK
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
IkarusTrojan-Spy.Win32.Agent
WebrootW32.Malware.Gen
GoogleDetected
McAfeeGenericRXAS-UE!BF81D4857A8D
VBA32TrojanPSW.Magania
TrendMicro-HouseCallTROJ_GEN.R002H06K623
RisingTrojan.Generic@AI.88 (RDML:pg+6FXDPeCY2qOIlAGwK2A)
MaxSecureTrojan.Malware.74274322.susgen
FortinetW32/GenericRXAS.UE!tr
DeepInstinctMALICIOUS

How to remove Malware.AI.279066997?

Malware.AI.279066997 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment