Malware

What is “Malware.AI.786192791”?

Malware Removal

The Malware.AI.786192791 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.786192791 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid

How to determine Malware.AI.786192791?


File Info:

name: CFBA66F4CCDB5A0502BA.mlw
path: /opt/CAPEv2/storage/binaries/fd0e0f20ba1408080d0ff055aaac416a4ac53e958c0d2ec53de076787c125272
crc32: C81BBAE3
md5: cfba66f4ccdb5a0502ba90411c29803d
sha1: ada32f0903829e64ebd2dd57da5c5f34cb83183d
sha256: fd0e0f20ba1408080d0ff055aaac416a4ac53e958c0d2ec53de076787c125272
sha512: 5cebf5640ffed1436406f1eb6db2080c1bd37582416b3f35a5c0aab9f35996ae330e4630f2630f705ddf7e0f9b332de796509fdd6bfd32ee198fc620738a2875
ssdeep: 3072:73QPerK9RDtD5XZUlfZhW7BnfsUpJ6I9Ms9Go/1wWJqHSDBlIZN2ymh7:9KDB5XCrhW7FffJLE4jI/2y47
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T158F38D2974C0C072C5A2053429F8DB76AA7DF9701F6A49EBB3D40B3E1FA11D16A34E67
sha3_384: f014d466f9037aab8fff8e982fc9f1aff7042bae6460a3b25593bb7589618fc77c79d9053b79e69d0a3f3d2c99f3e79e
ep_bytes: e806040000e97afeffff558becf64508
timestamp: 2018-11-18 18:42:39

Version Info:

FileVersion: 4.0.0.0
InternalName: service.exe
OriginalFilename: service.exe
ProductVersion: 4.0.0.0
Translation: 0x0409 0x04b0

Malware.AI.786192791 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Alinaos.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jatif.1709
ClamAVWin.Trojan.Alina-9789210-0
FireEyeGen:Variant.Jatif.1709
ALYacTrojan.Agent.Alinaos
Cylanceunsafe
ZillyaTrojan.Alinaos.Win32.125
SangforSpyware.Win32.Alinaos.Voro
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Alinaos.91417684
K7GWTrojan ( 00519c7e1 )
K7AntiVirusTrojan ( 00519c7e1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Alinaos.O
KasperskyTrojan-Spy.Win32.Alinaos.dm
BitDefenderGen:Variant.Jatif.1709
NANO-AntivirusTrojan.Win32.Alina.fkuzea
EmsisoftGen:Variant.Jatif.1709 (B)
F-SecureHeuristic.HEUR/AGEN.1305204
DrWebBackDoor.Alina.58
VIPREGen:Variant.Jatif.1709
McAfee-GW-EditionGeneric Trojan.hs
SophosMal/Generic-S
IkarusTrojan.AlinaOS
JiangminTrojanSpy.Alinaos.x
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1305204
Antiy-AVLTrojan[Spy]/Win32.Alinaos
XcitiumMalware@#2a4vgipwb3w0t
ArcabitTrojan.Jatif.D6AD
ViRobotTrojan.Win32.S.Alinaos.170616
ZoneAlarmTrojan-Spy.Win32.Alinaos.dm
GDataGen:Variant.Jatif.1709
GoogleDetected
AhnLab-V3Trojan/Win32.Alina.R267971
VBA32TrojanSpy.Alinaos
MAXmalware (ai score=94)
MalwarebytesMalware.AI.786192791
PandaTrj/Alina.C
TrendMicro-HouseCallTrojan.Win32.ALINAOS.THEOBAI
RisingTrojan.Alinaos!8.4C7 (TFE:5:dOZATFNtieC)
MaxSecureTrojan.Malware.74407230.susgen
FortinetW32/Alinaos.O!tr
DeepInstinctMALICIOUS

How to remove Malware.AI.786192791?

Malware.AI.786192791 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment