Malware

Malware.AI.621607732 removal tips

Malware Removal

The Malware.AI.621607732 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.621607732 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine Malware.AI.621607732?


File Info:

name: 6DE1211086B2A21548BD.mlw
path: /opt/CAPEv2/storage/binaries/fe209994e99c6fff13a89c73d0c6cb35cee3f9dde4e3e700f47960be4674c183
crc32: DC1E4DF3
md5: 6de1211086b2a21548bd2b1c1b9a3456
sha1: 3e53429e105da66b9b8879da3c0ff8ecf1decd08
sha256: fe209994e99c6fff13a89c73d0c6cb35cee3f9dde4e3e700f47960be4674c183
sha512: 0a1680e09ef2ef8ffca152cf4742dd07fb8ec0204cb14c4cd4e4f1fcd64f9a0acf40f5a4d32360293450f038709cfd05f6fed5dc9584b0660a0338fe6240bbb0
ssdeep: 3072:QdqanbcTeoch/CJd+fBfFVB4M3BHCiyiM/+CL6HjY2GCiMxIy8RGl:8BbcTeoUediaiM/UrZ78RU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA24AE3F1165A90AF0629E3002B5A462FC58AE71E7E2DC872F431E9AD1F54E8C77171B
sha3_384: f1036a1767402e1373081f05f870c819075637e7e239c765e104aba210618edfe36268c2186712183658bcf3833b3986
ep_bytes: 558bec81c434ffffffb8bdfc42008b10
timestamp: 2009-08-03 20:10:31

Version Info:

Comments:
CompanyName: Heaventools Software
FileDescription: Last Soft
FileVersion: 4.4.0.1110
InternalName: Last Soft
LegalCopyright: Copyright (c) 1991-2011 Heaventools
LegalTrademarks:
OriginalFilename: Laster.exe
ProductName: Last Soft
ProductVersion: 4.4.0.1110
Translation: 0x0409 0x04b0

Malware.AI.621607732 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Jorik.lvrm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Conjar.9
ClamAVWin.Trojan.Fakeav-3593
FireEyeGeneric.mg.6de1211086b2a215
CylanceUnsafe
ZillyaTrojan.FakeAV.Win32.90259
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/FlashApp.1c62fa03
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.086b2a
VirITTrojan.Win32.Fakealert.BEMV
CyrenW32/FakeAlert.PX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.NLI
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Conjar.9
NANO-AntivirusTrojan.Win32.Fakealert.dbspo
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Ht]
AvastWin32:MalOb-IJ [Cryp]
TencentWin32.Trojan.Generic.Bgow
Ad-AwareGen:Heur.Conjar.9
EmsisoftGen:Heur.Conjar.9 (B)
ComodoTrojWare.Win32.Kryptik.LXK@3193xw
DrWebTrojan.Fakealert.20613
VIPREGen:Heur.Conjar.9
TrendMicroTROJ_FAKEAV.SMUQ
McAfee-GW-EditionFakeAV-CN.gen.bm
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/FakeAV-AA
IkarusTrojan.Win32.FakeAV
GDataGen:Heur.Conjar.9
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.5EE
MicrosoftTrojanDownloader:Win32/Renos.PT
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAlert.R7722
McAfeeFakeAV-CN.gen.bm
TACHYONJoke/W32.FlashApp.214546
VBA32BScope.Trojan.Zbot.01393
MalwarebytesMalware.AI.621607732
TrendMicro-HouseCallTROJ_FAKEAV.SMUQ
RisingMalware.Undefined!8.C (TFE:4:A239jniEJ6P)
YandexTrojan.Kryptik!PQHqbqmYWlg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2322615.susgen
FortinetW32/PackZbot.D!tr
BitDefenderThetaGen:NN.ZexaF.34698.ny1@aqwmVKii
AVGWin32:MalOb-IJ [Cryp]
PandaAdware/ResonatorA
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.621607732?

Malware.AI.621607732 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment