Malware

Should I remove “Malware.AI.655167247”?

Malware Removal

The Malware.AI.655167247 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.655167247 virus can do?

  • Unconventionial language used in binary resources: Hebrew
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.655167247?


File Info:

name: B6794CFCBCE744DF1247.mlw
path: /opt/CAPEv2/storage/binaries/80e5989256a4db61de564cc0808fb43263b1111ab07f4ddc4e9e8847c212498f
crc32: BFFB5FD5
md5: b6794cfcbce744df1247a60f81b7a597
sha1: a7829f6187509989cb19a5f6834d3c1e17eda89e
sha256: 80e5989256a4db61de564cc0808fb43263b1111ab07f4ddc4e9e8847c212498f
sha512: 268aa887aa53951267e251f24e2bc43637ffeafad6bd0f5a9f49f5be52e450f18cfbf672b1b0e0695920d9e4b9cf1ca89c6fc07ea9851a25c45899ae868a3d3a
ssdeep: 384:QfYezDhV8laLd3kta9vBb1HNE84yBGNAhHiJ2GIqv0WdldjbPkZzrOJqn0B:Vla39HytyE8OXIqsEwZzaJqn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130137D63ABBC16A7F0660A36703157070CB1BC704DBACB5059C835DF9E5B5D1692F386
sha3_384: 942ab2dfd84c48d0c9a0d5d5bd58fbd05e06a9e26de3ae591853a9fd48fc8f48b3625c826dd25953df8d952913aa1626
ep_bytes: 60be000041008dbe0010ffff57eb0b90
timestamp: 2016-05-23 06:44:37

Version Info:

CompanyName: NirSoft
FileDescription: NirCmd
FileVersion: 2.81
InternalName: NirCmd
LegalCopyright: Copyright © 2003 - 2016 Nir Sofer
OriginalFilename: NirCmd.exe
ProductName: NirCmd
ProductVersion: 2.81
Translation: 0x0409 0x04b0

Malware.AI.655167247 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.68980624
FireEyeGeneric.mg.b6794cfcbce744df
SkyhighBehavesLike.Win32.Generic.pt
ALYacTrojan.GenericKD.68980624
Cylanceunsafe
SangforTrojan.Win32.Agent.V70z
CrowdStrikewin/grayware_confidence_70% (D)
ArcabitTrojan.Generic.D41C8F90
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Ransomware.Tovicrypt-9981641-0
BitDefenderTrojan.GenericKD.68980624
EmsisoftTrojan.GenericKD.68980624 (B)
VIPRETrojan.GenericKD.68980624
SophosGeneric ML PUA (PUA)
GoogleDetected
VaristW32/ABRisk.ALEK-4089
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win.Z.Ulpm.44544.A
GDataTrojan.GenericKD.68980624
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R300922
Acronissuspicious
McAfeeArtemis!B6794CFCBCE7
MAXmalware (ai score=80)
MalwarebytesMalware.AI.655167247
TrendMicro-HouseCallTROJ_GEN.R002H09I123
SentinelOneStatic AI – Suspicious PE
FortinetW32/ULPM.2C75!tr
DeepInstinctMALICIOUS

How to remove Malware.AI.655167247?

Malware.AI.655167247 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment