Malware

How to remove “Malware.AI.561859674”?

Malware Removal

The Malware.AI.561859674 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.561859674 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.561859674?


File Info:

name: F55D939B15C2339F3FAC.mlw
path: /opt/CAPEv2/storage/binaries/a6764ef7f7c143581a1959fab26440794d019919ab0e64c5f5f3d0730a855ec7
crc32: 503768EF
md5: f55d939b15c2339f3face73a4d5ca16a
sha1: c1e4a9cb62387624bf983692e80b654ea131dd07
sha256: a6764ef7f7c143581a1959fab26440794d019919ab0e64c5f5f3d0730a855ec7
sha512: 0ac1848e17c8fd4b8f6477342abb46e60e1e2f2a7bee86723868230b43a3f1cd640e19a336c8d9f0b8cc1d886baf921fe47ff5f780db6b1d69a24f491adcb1aa
ssdeep: 768:aKMupuyX6y9Z9QZv1+9p7vGZZijsjNfx1afirwSl/Aw:aFcuyXJ9Z9+mpaZZijUx1Qi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5D36D6BBE4441E3D0070034251ABB7F6AE25831835EAE53EF81D9875CF8996F879D0B
sha3_384: db3bb4a8c6fe4a17e0c8ae95452d40edc383f9a712a1d58990ecb06279b3c30d3df5a03dee42da89f994a2253f17ab2e
ep_bytes: 558bec6aff6800224000684060400064
timestamp: 2016-12-02 05:05:12

Version Info:

0: [No Data]

Malware.AI.561859674 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.m2Bz
MicroWorld-eScanGen:Trojan.NetworkWorm.imW@auxBiadb
ClamAVWin.Worm.Lapka-9757211-0
FireEyeGeneric.mg.f55d939b15c2339f
CAT-QuickHealDdos.Nitol.18525
McAfeePolyPatch-UPX
MalwarebytesMalware.AI.561859674
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaDDoS:Win32/Lapka.1e553ccf
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.b15c23
BitDefenderThetaAI:Packer.F43661651F
CyrenW32/Farfli.CP.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/ServStart.D
ZonerTrojan.Win32.58903
APEXMalicious
CynetMalicious (score: 100)
KasperskyRootkit.Win32.Lapka.an
BitDefenderGen:Trojan.NetworkWorm.imW@auxBiadb
NANO-AntivirusTrojan.Win32.ServStart.emenlu
AvastWin32:GenMalicious-BKJ [Trj]
TencentTrojan.Win32.Lapka.bw
EmsisoftGen:Trojan.NetworkWorm.imW@auxBiadb (B)
BaiduWin32.Trojan.ServStart.a
F-SecureWorm.WORM/Rbot.Gen
DrWebTrojan.DnsAmp.28
VIPREGen:Trojan.NetworkWorm.imW@auxBiadb
TrendMicroTROJ_NITOL.SMN1
McAfee-GW-EditionBehavesLike.Win32.Generic.cz
Trapminemalicious.high.ml.score
SophosTroj/Nitol-AR
IkarusWorm.Win32.ServStart
GDataWin32.Worm.ServStart.B
JiangminTrojanDropper.Dinwod.ke
AviraWORM/Rbot.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan[Rootkit]/Win32.Lapka.an
XcitiumTrojWare.Win32.ServStart.E@555zmt
ArcabitTrojan.NetworkWorm.EFD2232
ViRobotTrojan.Win.Z.Servstart.135168.EX
ZoneAlarmRootkit.Win32.Lapka.an
MicrosoftDDoS:Win32/Nitol.A
GoogleDetected
AhnLab-V3Dropper/Win32.Nitol.R107037
VBA32BScope.TrojanDDoS.Macri
ALYacGen:Trojan.NetworkWorm.imW@auxBiadb
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_NITOL.SMN1
RisingTrojan.DDOS!1.AF40 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ServStart.GL!tr
AVGWin32:GenMalicious-BKJ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.561859674?

Malware.AI.561859674 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment