Malware

Malware.AI.491986641 removal instruction

Malware Removal

The Malware.AI.491986641 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.491986641 virus can do?

  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

ff.feloon.com

How to determine Malware.AI.491986641?


File Info:

crc32: BEB3C10E
md5: 946a9cf2483d84c359bfb3e582e3ce75
name: 946A9CF2483D84C359BFB3E582E3CE75.mlw
sha1: 9399c6cbec1c901265c932f0cd5b0a6b0454b8be
sha256: 7fa354cc033dd93d8e4326d93c6a02176721bfa2012623fb8b7c357d9d064fd2
sha512: d0eafc991f90c1bcfdbccdccef68b0ae910e65ee50549dd3e8ffd2f6e6f0e4e97662869390854ca3df900f388ad37b4318bed76a0154dd48767363c6a4207361
ssdeep: 3072:2fSAfQeIGZ3Xv+R1qtXFqlZ3Xv+R1qtXFqSfSAfQeIGZ3Xv+R1qtXFq:2frQpqv+jCYvv+jCYSfrQpqv+jCY
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Malware.AI.491986641 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 000c64881 )
DrWebBackDoor.Siggen.54016
CynetMalicious (score: 100)
ALYacGen:Variant.Doina.21894
CylanceUnsafe
ZillyaTrojan.Agent.Win32.399972
K7GWTrojan ( 000c64881 )
Cybereasonmalicious.2483d8
BaiduWin32.Trojan.Staser.g
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.PSP
APEXMalicious
AvastWin32:Agent-AYDH [Trj]
KasperskyUDS:Trojan.Win32.Staser
BitDefenderGen:Variant.Doina.21894
NANO-AntivirusTrojan.Win32.TrjGen.ecsyrq
MicroWorld-eScanGen:Variant.Doina.21894
TencentMalware.Win32.Gencirc.10ba4ccd
Ad-AwareGen:Variant.Doina.21894
SophosMal/Generic-S
ComodoMalware@#57jb72u1mfg2
BitDefenderThetaGen:NN.ZexaF.34294.nmJfaiSQqlai
McAfee-GW-EditionBehavesLike.Win32.Downloader.dc
FireEyeGeneric.mg.946a9cf2483d84c3
EmsisoftGen:Variant.Doina.21894 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Tofsee.ef
AviraHEUR/AGEN.1111692
Antiy-AVLTrojan/Generic.ASMalwS.9E938B
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Doina.D5586
GDataGen:Variant.Doina.21894 (2x)
AhnLab-V3Trojan/Win32.Tepfer.R70097
McAfeeArtemis!946A9CF2483D
MAXmalware (ai score=87)
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.491986641
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!buDPQyg5+Zw
IkarusTrojan-Downloader.Win32.Small
FortinetW32/Generic.AP.1A8DC6!tr
AVGWin32:Agent-AYDH [Trj]

How to remove Malware.AI.491986641?

Malware.AI.491986641 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment