Malware

Malware.AI.43858848 (file analysis)

Malware Removal

The Malware.AI.43858848 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.43858848 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.43858848?


File Info:

name: BCF54D00ABC755D2CF73.mlw
path: /opt/CAPEv2/storage/binaries/bc85e8f33704d722a5225c5063e45eb8a5d59def5b60c3aa5d3882123e91dd0c
crc32: AA6C09D6
md5: bcf54d00abc755d2cf73d0a9fb620542
sha1: b11de659e66b59e8d3842371c6620f4e2be8c357
sha256: bc85e8f33704d722a5225c5063e45eb8a5d59def5b60c3aa5d3882123e91dd0c
sha512: c19ba11f8d3e3127ace973650c5048f3272925988f15e5ed48879927653b47fb679c9918a376f7f40d861d5b3f764967b1753bdb4129efa574930e1805c0c8c7
ssdeep: 98304:V6qCz7U5BETtVCWXESBUkT9e0WKPVVd6R61yd1UkT:0qm7U5KtVCWXFUkT8IVY6G1UkT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B6A63304393C5C6BC723407BA2E2D7FDE96D5F12AE19A4625DC877870B3239D8762227
sha3_384: c37faf1c94f77348a6cd91dc5a66f15e08308f284bc43986bc97f4a2475ded5a09ba3fb74b7579bd007cbbbde16e4dd8
timestamp: 2015-11-10 06:08:30

Version Info:

FileVersion: 6.6.39.533
Comments: WanDrv6.6 - ITianKong.Com
FileDescription: 万能驱动助理主程序
ProductVersion: 6.6
LegalCopyright: Copyright 2006-2015 ITianKong.Com, All Rights Reserved.
OriginalFilename: WanDrv6.exe
ProductName: 万能驱动助理
InternalName: 万能驱动
CompanyName: IT天空(ITianKong.Com)
Compiler: SKAE
Translation: 0x0804 0x04b0

Malware.AI.43858848 also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.Generic.1!c
FireEyeGeneric.mg.bcf54d00abc755d2
MalwarebytesMalware.AI.43858848
SangforTrojan.Win32.Save.a
K7AntiVirusUnwanted-Program ( 0059886f1 )
AlibabaPacked:Win32/Pioneer.3f878aa1
K7GWUnwanted-Program ( 0059886f1 )
CrowdStrikewin/malicious_confidence_90% (W)
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.AutoIt.PC
APEXMalicious
ClamAVWin.Malware.Autoit-7733445-0
AvastWin32:Pioneer-C
RisingTrojan.Obfus/Autoit!1.D77B (CLASSIC)
McAfee-GW-EditionBehavesLike.Win32.RealProtect.tt
SophosGeneric Reputation PUA (PUA)
GDataWin32.Trojan.Agent.ABF9CN
Antiy-AVLVirus/Win32.Floxif
XcitiumHeur.Corrupt.PE@1z141z3
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Cylanceunsafe
FortinetW32/PossibleThreat
AVGWin32:Pioneer-C
Cybereasonmalicious.9e66b5
DeepInstinctMALICIOUS

How to remove Malware.AI.43858848?

Malware.AI.43858848 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment