Malware

Malware.AI.2799704472 removal

Malware Removal

The Malware.AI.2799704472 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2799704472 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2799704472?


File Info:

name: 9F1F82283BD130439D69.mlw
path: /opt/CAPEv2/storage/binaries/06e1fe7c36ec6f13881b5b5a008579ec8a0e0fe543b6fd92403d236a2a61ec7e
crc32: 41E8E65A
md5: 9f1f82283bd130439d697aacaa671f3a
sha1: 92bc9ef1c71401867a1456747bb82cb766ba9c87
sha256: 06e1fe7c36ec6f13881b5b5a008579ec8a0e0fe543b6fd92403d236a2a61ec7e
sha512: fb524c1acc0f46a9462015f94557987f8a5a5169afec4aa6daa11111cb1d997d1f038520cfc3bfb479aaf0e58f053f4af121290caac6d630d339cb1ba3d7abeb
ssdeep: 49152:2d+U7J17z5wsde3v895zu3ck3aq7MepXV6DPsvodh7xAVox52ms8V+EFAe:2d+UV17zC3kru3ta/7DUw2qxYm+2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147E533C97B054E5DC8BC43749E21DDAC4A7AAE693E72C68E7491731E0BB32E59C02C47
sha3_384: 46dede6df283af803f0e1316f6559669962a6965edc643a30725febe809a5902171512db1cb4a383487e5ed6e79d3512
ep_bytes: 60be0070b9008dbe00a086ff5789e58d
timestamp: 2021-12-06 15:50:45

Version Info:

FileVersion: 2.1.12.6
FileDescription: 易语言程序
ProductName: 闪豆视频下载器
ProductVersion: 2.1.12.6
CompanyName: 失去同步
LegalCopyright: 仅用于学习,请勿非法用途
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Malware.AI.2799704472 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
CAT-QuickHealRisktool.Flystudio.18826
SkyhighBehavesLike.Win32.Flyagent.wc
McAfeeArtemis!9F1F82283BD1
MalwarebytesMalware.AI.2799704472
SangforTrojan.Win32.Save.a
Cybereasonmalicious.1c7140
BitDefenderThetaGen:NN.ZexaF.36680.apKfaCh3LopH
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Trojanx-9951053-0
AvastWin32:TrojanX-gen [Trj]
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1TYMTF4
VaristW32/Trojan.IRG.gen!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
GoogleDetected
TrendMicro-HouseCallTROJ_GEN.R002V01K923
IkarusTrojan.Win32
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.2799704472?

Malware.AI.2799704472 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment