Malware

Malware.AI.61696254 (file analysis)

Malware Removal

The Malware.AI.61696254 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.61696254 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Y0da
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.61696254?


File Info:

name: 2A93D6E9B2D0CF40CFCA.mlw
path: /opt/CAPEv2/storage/binaries/c894ae27d447449dd99322ddc05ce049d1653854a7b2331fd3ed4cc61b15eed4
crc32: C5E19AD2
md5: 2a93d6e9b2d0cf40cfcadee46620a209
sha1: 2a4b379931219c3808ab47f30b872b1ed827ec18
sha256: c894ae27d447449dd99322ddc05ce049d1653854a7b2331fd3ed4cc61b15eed4
sha512: 2d3b7e419cf3df2acb7c3343d81bafcb89c1f2f81146e489c5bf2334b8332777453873a4f69659f09d87e21c58c81ea5f7cfc5e1ee56282cb117e32c9eb85723
ssdeep: 24576:qfhhfX8HCjCAd0SsFB6JY7OFTrYmgumJmnaOu:wvECGA2NFB6u0T0burnaOu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB553315CB900E90CFB91EB902A7893A5692A8497F74DFDF1206592DF431BC36C36BB1
sha3_384: 2cef002af3d73a20b9a06b78074bb7e68b71cf525df4f0c14cd4a161053214e02a37e18aa2168225474301fa9247d4cb
ep_bytes: 60e80000000083c4048b6c24fce8c402
timestamp: 2008-04-13 18:32:45

Version Info:

0: [No Data]

Malware.AI.61696254 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Banbra.lHam
tehtrisGeneric.Malware
DrWebBackDoor.Pigeon.5102
MicroWorld-eScanTrojan.GenericKD.62264356
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.33345
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/Buzus.0540546a
Cybereasonmalicious.931219
CyrenW32/RLPacked.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.AEC
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Buzus-19712
KasperskyTrojan.Win32.Buzus.dtry
BitDefenderTrojan.GenericKD.62264356
NANO-AntivirusTrojan.Win32.Black.bsyik
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Keylogger.Czlw
Ad-AwareTrojan.GenericKD.62264356
SophosMal/Generic-S
ComodoTrojWare.Win32.Downloader.Agent.bjts@23sju0
McAfee-GW-EditionBehavesLike.Win32.Infected.th
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.2a93d6e9b2d0cf40
EmsisoftTrojan.GenericKD.62264356 (B)
IkarusTrojan-Downloader.Win32.Refroso
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1B
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.62264356
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Buzus.C51121
Acronissuspicious
McAfeeArtemis!2A93D6E9B2D0
MAXmalware (ai score=100)
VBA32Trojan.Buzus
MalwarebytesMalware.AI.61696254
ZonerProbably Heur.ExeHeaderP
RisingTrojan.Win32.Nodef.ejj (CLOUD)
YandexTrojan.Buzus!DnCDUx0Bmus
MaxSecureTrojan.Malware.1370647.susgen
FortinetW32/Buzus.DTRY!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.61696254?

Malware.AI.61696254 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment