Malware

Malware.AI.61945979 information

Malware Removal

The Malware.AI.61945979 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.61945979 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.61945979?


File Info:

name: 6FE72838FB59E5E3175B.mlw
path: /opt/CAPEv2/storage/binaries/09551d73cf67b8036a88561b9da94594485a2d691b11ca40c21da2fbcded718f
crc32: 08E88ADF
md5: 6fe72838fb59e5e3175b7ba14fc6842a
sha1: cd6557d491e64615abdcadde1c34619c4abfe18c
sha256: 09551d73cf67b8036a88561b9da94594485a2d691b11ca40c21da2fbcded718f
sha512: 7078a8d073cdb1b86b85fbf0677805808d35f81235b3ed2bc586cd7f9e3a5e05b89a19e217776b962fb24af3df1fdba82f7e8f2bae371ce0b2cd2fa0c70cf9f1
ssdeep: 3072:yeqSMQcPcVB+063daqiBpCTBfRl7R6BGZWIPw4JXd:TUQMci9dadCTBJlMBDIPT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174E38D2133E0D033D1B601328EE2C6696676B8A58FB181CB78DC376FAD746E296747C5
sha3_384: 08df487d03816629cd2fc7572084bf358e42a1c16094ef43fc0d4d2934027b5e2ace2ee2e482728b7dc0aaf9d9763dc8
ep_bytes: 60be00c042008dbe0050fdff57eb0b90
timestamp: 2011-11-04 16:47:11

Version Info:

FileVersion: 2.0.2.1
PrivateBuild: 1799
ProductVersion: 2.0.2.1
Translation: 0x0809 0x04b0

Malware.AI.61945979 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Heur.KS.1
ClamAVWin.Malware.Cycbot-6997838-0
ALYacGen:Trojan.Heur.KS.1
CylanceUnsafe
SangforVirus.Win32.Save.a
Cybereasonmalicious.8fb59e
CyrenW32/FraudLoad.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Trojan.Heur.KS.1
AvastWin32:Cycbot-RZ [Trj]
Ad-AwareGen:Trojan.Heur.KS.1
EmsisoftGen:Trojan.Heur.KS.1 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPREGen:Trojan.Heur.KS.1
McAfee-GW-EditionRDN/Generic BackDoor
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.6fe72838fb59e5e3
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataGen:Trojan.Heur.KS.1
AviraHEUR/AGEN.1248279
Antiy-AVLTrojan/Generic.ASMalwS.6C82
ArcabitTrojan.Heur.KS.1
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Backdoor/Win.Gbot.R502716
Acronissuspicious
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=89)
MalwarebytesMalware.AI.61945979
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ULPM.16C0!tr
BitDefenderThetaAI:Packer.3B02961514
AVGWin32:Cycbot-RZ [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.61945979?

Malware.AI.61945979 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment