Malware

Malware.AI.42795081 malicious file

Malware Removal

The Malware.AI.42795081 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.42795081 virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.42795081?


File Info:

name: AA56E75A7FE01C368BF2.mlw
path: /opt/CAPEv2/storage/binaries/df7e4b6b56cbf0b5bf5954448877fcba31d9bdc7eeea44feb9ec090061c33b09
crc32: 878F481D
md5: aa56e75a7fe01c368bf25440b2e901af
sha1: 655288724f66070b9bc0ec3a7a999fd28b1aff6c
sha256: df7e4b6b56cbf0b5bf5954448877fcba31d9bdc7eeea44feb9ec090061c33b09
sha512: f3ce52d566058c9663d4c983b9366545b83052244b3ec7b747be78c6d5c36bea3ea2e3c855d49168b0adbbdf5b61792aa146716ff751fc11492740d29923bcee
ssdeep: 768:DqgGgNkNk2SJCW5G88e2fsEyozm6W3+Ow9VL7THu:DqXgN9FxGA20oztLOw9VL7C
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18023EA07F74591D5DDEA96F008D7C2E751E77C6C4B0646076B7036BDB83CA231C9AA82
sha3_384: 9f5a8a301dd044a99ab44e52799005d73f22d72f64a8fdb79e7e77e10ed824958a1ff944f8872e608dcfceabf0ab866b
ep_bytes: 68e0134000e8f0ffffff000048000000
timestamp: 2010-03-23 14:56:53

Version Info:

Translation: 0x0409 0x04b0
ProductName: AUcm1YvWzL
FileVersion: 1.00
ProductVersion: 1.00
InternalName: 13
OriginalFilename: 13.exe

Malware.AI.42795081 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.AutoRun.mCon
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Chinky.4
FireEyeGeneric.mg.aa56e75a7fe01c36
CAT-QuickHealTrojan.VBCrypt.MF.930
SkyhighBehavesLike.Win32.Generic.pz
ALYacGen:Trojan.Chinky.4
Cylanceunsafe
ZillyaWorm.AutoRun.Win32.27632
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
AlibabaWorm:Win32/AutoRun.fe604693
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.24f660
VirITWorm.Win32.Generic.AYZF
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.AutoRun.bfim
BitDefenderGen:Trojan.Chinky.4
AvastWin32:AutoRun-BHK [Wrm]
EmsisoftGen:Trojan.Chinky.4 (B)
F-SecureWorm.WORM/AutoRu.bfim.69
DrWebWin32.HLLW.Autoruner.57078
VIPREGen:Trojan.Chinky.4
Trapminemalicious.moderate.ml.score
SophosMal/VBCheMan-A
GDataGen:Trojan.Chinky.4
WebrootW32.Malware.Gen
GoogleDetected
AviraWORM/AutoRu.bfim.69
Antiy-AVLWorm/Win32.AutoRun
KingsoftWin32.Worm.AutoRun.bfim
XcitiumWorm.Win32.Autorun.~bfi@27twe1
ArcabitTrojan.Chinky.4
ZoneAlarmWorm.Win32.AutoRun.bfim
MicrosoftTrojan:Win32/Dynamer!dtc
AhnLab-V3Worm/Win32.AutoRun.C196668
McAfeeSwisyn.x
MAXmalware (ai score=100)
MalwarebytesMalware.AI.42795081
PandaGeneric Malware
RisingWorm.Autorun!1.99ED (CLASSIC)
YandexWorm.AutoRun!1Albw4/5Qu8
IkarusWorm.Win32.AutoRun
MaxSecureTrojan.Malware.1396282.susgen
FortinetW32/SillyFDC.F!tr
AVGWin32:AutoRun-BHK [Wrm]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.42795081?

Malware.AI.42795081 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment