Malware

Malware.AI.31770942 malicious file

Malware Removal

The Malware.AI.31770942 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.31770942 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Malware.AI.31770942?


File Info:

name: D5A4FD6755EDED2CB7E9.mlw
path: /opt/CAPEv2/storage/binaries/f1b7d3910bcd4eccba19c2a07b0424856240d1ca712b1faf658fb5f60df5e687
crc32: 8A1BC69D
md5: d5a4fd6755eded2cb7e9640500171d23
sha1: 6478f843ca5c018c40687590e36fb3a8c16a31c3
sha256: f1b7d3910bcd4eccba19c2a07b0424856240d1ca712b1faf658fb5f60df5e687
sha512: 86938fa4d548f84dfa0240629ea5ab44626adcdc645f67b5b79cecc56026939c193bf89b27c908909b645d440e4a1f2e171ac39851373bb7a020b8b56615bade
ssdeep: 98304:QkLvMbGTt49gXFbFqvb9/vJtkh7dAy9QdB4BC+4fo8os9YYHo9tHT55lji:PUKt7wbV50aB4hjYIjHlnG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F046123BF268A43EC4AB5A3145739220997BBA61791A8C0F47FC384DCF365601E3B756
sha3_384: 043b6796d3baa0b62e904d5c307efb0624af65346d97c35381937f543b0b90373b5991f58d785791ea32f2d1d8988c4d
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2022-04-14 16:10:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: cgbiosogqpwoq Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: cgbiosogqpwoq
ProductVersion: 101.100.05
Translation: 0x0000 0x04b0

Malware.AI.31770942 also known as:

MicroWorld-eScanTrojan.GenericKD.62915742
FireEyeTrojan.GenericKD.62915742
McAfeeArtemis!D5A4FD6755ED
CylanceUnsafe
K7AntiVirusTrojan ( 005993801 )
K7GWTrojan ( 005993801 )
SymantecTrojan.Gen.2
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/GenCBL.CVS
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.62915742
AvastWin32:Evo-gen [Trj]
SophosMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
GDataWin32.Trojan-Stealer.TinyNuke.KY5VXW
WebrootW32.Trojan.Emotet
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
MAXmalware (ai score=86)
MalwarebytesMalware.AI.31770942
TrendMicro-HouseCallTROJ_GEN.R002H0DJI22
RisingTrojan.MalCert!1.E087 (CLASSIC)
IkarusWin32.Outbreak
FortinetW32/GenCBL.CVS!tr
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Malware.AI.31770942?

Malware.AI.31770942 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment