Malware

How to remove “Malware.AI.3111870945”?

Malware Removal

The Malware.AI.3111870945 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3111870945 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.3111870945?


File Info:

name: BF20270E7CF2510AB167.mlw
path: /opt/CAPEv2/storage/binaries/ff605a9965408284218e0819da17ffa59593f7cdebb627f9048add53e679a4e2
crc32: E762AA23
md5: bf20270e7cf2510ab1674959ee960a6f
sha1: fcaa5609bea6184df097cb734a7e90564a30b4a5
sha256: ff605a9965408284218e0819da17ffa59593f7cdebb627f9048add53e679a4e2
sha512: caa983012dadcce1d7d9265932ed4fee7a5a1f409e4cbafb7275f35e2b7a071d93202ef2970a496094bd1309ad97b587166ba1584a24bb41b1e409d0481bfab4
ssdeep: 1536:OaUyWqaNuiMr5w3gGdC+Tmhg+x5Z8IQQ:FfWqaQTwQGQ+Tmhg+xX8g
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19AC3F043FE43E9C3F27D8930DCA69E7585D16BBFCA23052A749CF6DCA72B5660405A02
sha3_384: 59588b52f7a48f1b07e079937296cdbaa5da2aa4e495c69db4f06b87e12a67e8fd766877dc948a3510f49ad11ea36b58
ep_bytes: 68642e4000e8eeffffff000050000000
timestamp: 2008-07-07 01:55:06

Version Info:

Translation: 0x0804 0x04b0
Comments: 设计:谢云龙
CompanyName: 水晶情缘工作室
FileDescription: 系统加速专家
LegalCopyright: http://www.lovehy.com
LegalTrademarks: 系统加速专家
ProductName: 系统加速专家
FileVersion: 2008.00
ProductVersion: 2008.00
InternalName: hyfast
OriginalFilename: hyfast.exe

Malware.AI.3111870945 also known as:

LionicTrojan.Win32.Bulz.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.446936
FireEyeGeneric.mg.bf20270e7cf2510a
McAfeeRDN/Generic.hbg
CylanceUnsafe
SangforSuspicious.Win32.Bulz.446936
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanDownloader:Win32/Generic.e7e34091
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Bulz.446936
AvastFileRepMetagen [Malware]
Ad-AwareGen:Variant.Bulz.446936
SophosGeneric ML PUA (PUA)
TrendMicroTROJ_GEN.R011C0PK121
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftGen:Variant.Bulz.446936 (B)
IkarusTrojan.VB.Downloader
AviraTR/VB.Downloader.Gen6
MAXmalware (ai score=85)
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win32.Z.Bulz.124928
GDataGen:Variant.Bulz.446936
CynetMalicious (score: 100)
Acronissuspicious
ALYacGen:Variant.Bulz.446936
MalwarebytesMalware.AI.3111870945
TrendMicro-HouseCallTROJ_GEN.R011C0PK121
SentinelOneStatic AI – Malicious PE
FortinetW32/PossibleThreat
AVGFileRepMetagen [Malware]

How to remove Malware.AI.3111870945?

Malware.AI.3111870945 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment