Malware

Malware.AI.891533393 malicious file

Malware Removal

The Malware.AI.891533393 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.891533393 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid

How to determine Malware.AI.891533393?


File Info:

name: FAA008C291369CB85E51.mlw
path: /opt/CAPEv2/storage/binaries/28890db8128ba6a66140967c870f9ae70bfca6a23493ac67616ed97e3546bc9a
crc32: 47C7F9E7
md5: faa008c291369cb85e5102cf83d20751
sha1: fae6caf90d2a44c7fd52493f8efaf0f02b2d8f72
sha256: 28890db8128ba6a66140967c870f9ae70bfca6a23493ac67616ed97e3546bc9a
sha512: 2d89809b37720a7939f2d5d9fbb80459ef20f4471eb1ea972a33c52cb944732e6acb5b22ff2396dc847c54f5f4a6fb2921d4da1daf1571a6ed2b37269a0f1574
ssdeep: 12288:Gk/UJRcOSjXO0J4LiyqYojgLEAW503U7sXVmIP5A7PJvnejOk:Gk/U8O6Og4Lg27WiXh5kPJvnej
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8F401C7D36A4CCDD4610E72E4F3D4E167E3DC2724369A911A30B929AF721A34C7B64A
sha3_384: 1689187ff9456dbe82a47cc2ccb4cd5c351eace9b5b168996081d294c0cf878dcffdba86f757d106d64eb26b7a20eff8
ep_bytes: 60e80000000058059f0200008b3003f0
timestamp: 2022-02-04 09:08:31

Version Info:

Comments:
CompanyName: TubeMate Software
FileDescription: TubeMate Player
FileVersion: 3, 26, 5, 0
InternalName: TubeMate Player
LegalCopyright: (C) TubeMate Software. All rights reserved.
LegalTrademarks:
OriginalFilename: TubeMatePlayer.EXE
PrivateBuild:
ProductName: Windows TubeMate
ProductVersion: 3, 26, 5, 0
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.AI.891533393 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Vtflooder.lnTD
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38896189
FireEyeGeneric.mg.faa008c291369cb8
McAfeeArtemis!FAA008C29136
BitDefenderThetaGen:NN.ZexaF.34182.Um0@aS1IbFgi
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.38896189
AvastFileRepMalware
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionArtemis
EmsisoftTrojan.GenericKD.38896189 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
GridinsoftRansom.Win32.Wacatac.sa
GDataTrojan.GenericKD.38896189
AhnLab-V3Trojan/Win.Generic.R460347
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=86)
MalwarebytesMalware.AI.891533393
APEXMalicious
RisingMalware.Heuristic!ET#85% (RDMK:cmRtazqdbmUNAbnquMSqcqzNlar1)
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.891533393?

Malware.AI.891533393 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment