Malware

Malware.AI.530645204 information

Malware Removal

The Malware.AI.530645204 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.530645204 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • HTTPS urls from behavior.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.530645204?


File Info:

name: B94B8E24FD97AABCFB00.mlw
path: /opt/CAPEv2/storage/binaries/fc7a17d934859e99af16e3481b1e37d18a3a53e62ca9c7dce68a37efb5723b61
crc32: 80AE01BA
md5: b94b8e24fd97aabcfb0021c46e2d11c9
sha1: 9009fcb44e0223a50de03a03848a71f93d9d5a53
sha256: fc7a17d934859e99af16e3481b1e37d18a3a53e62ca9c7dce68a37efb5723b61
sha512: c2e822af37667bc77049184225c3c45c9d78973d15e0c884fd2c6b3845efd414b08ef6a4f030a86678172ca9c4af6ca1b3890dcd2fe1388a6f179a0138a5a839
ssdeep: 98304:/FRUqMGR+e7t4QI5zEKKJA7/kYMqgOBfx9AM2thfod+egJcFHI:/dMve72zEKp4YgOBfRkC4c1I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126262311BAE0C076C0460533257BEF059E6BE591DB266F8B7BE512BDCF309816A3631E
sha3_384: 3b24dd3ef89128398c90cb6aa81380c546e17a1169ef1563ac8ffd581227b059782556081b266ad4e3353c1f9ce2e9de
ep_bytes: e8f5660000e979feffff3b0df04d4400
timestamp: 2014-08-08 12:03:16

Version Info:

FileDescription: 游戏安装包
FileVersion: 2, 3, 8, 8
InternalName: start
LegalCopyright: Copyright (C) 2014
OriginalFilename: start.exe
ProductName: 安装包
ProductVersion: 2, 3, 8, 8
Translation: 0x0804 0x04b0

Malware.AI.530645204 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.16462
ALYacGen:Variant.Doina.16462
MalwarebytesMalware.AI.530645204
VIPREGen:Variant.Doina.16462
K7AntiVirusUnwanted-Program ( 00587b9f1 )
K7GWUnwanted-Program ( 00587b9f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.YouXun.Y
APEXMalicious
KasperskyTrojan-Dropper.Win32.Gamedrop.b
BitDefenderGen:Variant.Doina.16462
NANO-AntivirusRiskware.Win32.YouXun.euwqrj
AvastWin32:Malware-gen
RisingAdware.YouXun!1.E121 (CLASSIC)
EmsisoftGen:Variant.Doina.16462 (B)
F-SecureHeuristic.HEUR/AGEN.1303997
DrWebTrojan.DownLoader22.1574
ZillyaAdware.AgentCRT.Win32.494
FireEyeGeneric.mg.b94b8e24fd97aabc
GDataGen:Variant.Doina.16462
JiangminTrojanDropper.Gamedrop.u
AviraHEUR/AGEN.1303997
MAXmalware (ai score=89)
Antiy-AVLTrojan[Dropper]/Win32.Gamedrop
XcitiumApplication.Win32.InstallCore.HAOS@5iwj73
ArcabitTrojan.Doina.D404E
ZoneAlarmTrojan-Dropper.Win32.Gamedrop.b
MicrosoftPUA:Win32/Youxun
CynetMalicious (score: 99)
VBA32BScope.Adware.ArcadeWeb
TencentMalware.Win32.Gencirc.10beaba0
MaxSecureDropper.Dropper.Win32.Gamedrop.b_211284
AVGWin32:Malware-gen
CrowdStrikewin/grayware_confidence_70% (D)

How to remove Malware.AI.530645204?

Malware.AI.530645204 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment