Malware

About “Malware.AI.921784639” infection

Malware Removal

The Malware.AI.921784639 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.921784639 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools

How to determine Malware.AI.921784639?


File Info:

name: 3FAE8F3EB76C031445BD.mlw
path: /opt/CAPEv2/storage/binaries/f99a8bfeb52d6a0db83f1d7aed041aca4aac737dd78b5e52e490928cd33a54d0
crc32: 3E1CAE61
md5: 3fae8f3eb76c031445bdc5facd55dc81
sha1: 08261d86716dac929934a30f2aa5d78578b29ef1
sha256: f99a8bfeb52d6a0db83f1d7aed041aca4aac737dd78b5e52e490928cd33a54d0
sha512: 159862ad050d6683ebfec953469bb61ebf560e468aba8804ae44e04b4f3dc1bd2e685d964287a3f9cafaac0af03d2c9f285e1ccb0c5ae34d5fe0526333f11f54
ssdeep: 98304:GJz1Cw4D9uuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuuTuuuuuuuuuuuuuuuuuuuuU:GADeuMpF4lAwVbIhQeVmbs5ZU0GPRX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190363390B002EA1CE55D1E31E66AC7F461975CC0F5941A2F13EA3E293DFA1F0BB52C99
sha3_384: d4dde0410b7a3367b19d6bf0f104f8f69dbea4d92d1697d231210462610408b2070c7f719714acb3a9cf96641d5069c6
ep_bytes: e80200000036ed8734248db646ffffff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.921784639 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.324763
McAfeeBackDoor-EXZ
CylanceUnsafe
VIPREGen:Variant.Zusy.324763
Cybereasonmalicious.eb76c0
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.ZProtect.D suspicious
APEXMalicious
BitDefenderGen:Variant.Zusy.324763
AvastWin32:Evo-gen [Susp]
Ad-AwareGen:Variant.Zusy.324763
EmsisoftGen:Variant.Zusy.324763 (B)
ComodoMalware@#2oi7odjm8z6zt
McAfee-GW-EditionBehavesLike.Win32.VirRansom.rc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/EncPk-ANJ
IkarusBackdoor.Win32.Zegost
AviraBDS/Hupigon.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Zusy.324763
CynetMalicious (score: 100)
MAXmalware (ai score=89)
MalwarebytesMalware.AI.921784639
YandexTrojan.GenAsa!aZbmbqdA6Rk
SentinelOneStatic AI – Malicious PE
AVGWin32:Evo-gen [Susp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.921784639?

Malware.AI.921784639 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment