Malware

Malware.AI.928331009 removal instruction

Malware Removal

The Malware.AI.928331009 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.928331009 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the Nitol malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.928331009?


File Info:

name: A97CFB801C9A74F42EC9.mlw
path: /opt/CAPEv2/storage/binaries/06350a4b80691e2a89951d777eb184ce7f405bcbd9b29805ebc53c32ea8ee1c3
crc32: 962F1CC1
md5: a97cfb801c9a74f42ec92722a7ef7b69
sha1: ab35b79a2db75f8ec2108cfd925d5b59056af785
sha256: 06350a4b80691e2a89951d777eb184ce7f405bcbd9b29805ebc53c32ea8ee1c3
sha512: 662636f0ca965e2a357762f0261e882586051abd10327037a248fd5765a4e3d32c8b9484e5a1a15b3625dc99d71a3b9fc20454f160e35a72bf5b29f9f88ae2d9
ssdeep: 3072:fZYhjFTttfP9ZGFwgvRLLCzOYFDq+UdnIPPlMzcsofIw+KaX0LcHLkMIIRm:BYhhT96wgvRHCzOYtqlGyzcsX3KA0LQg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17F14F14D2E934127D88486B085D10EE90BFCAC573D8275AFEF7098161E640AD96F89FB
sha3_384: 4d93fd8ce1e028bbfe2dfaf0a84ad924207f20800fc4b5e50ae3bde8a323b182efca3799f9a852d5f27c626c3a7e7e74
ep_bytes: 558bec6aff68e060400068403d400064
timestamp: 2011-12-12 13:56:19

Version Info:

0: [No Data]

Malware.AI.928331009 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.94869
FireEyeGeneric.mg.a97cfb801c9a74f4
CAT-QuickHealBackdoor.Zegost.B
ALYacTrojan.GenericKDZ.94869
MalwarebytesMalware.AI.928331009
VIPRETrojan.GenericKDZ.94869
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 003245d21 )
K7GWTrojan ( 003245d21 )
Cybereasonmalicious.01c9a7
BaiduWin32.Trojan.Dialer.d
VirITTrojan.Win32.Dialer.AHYB
CyrenW32/Zegost.VONC-5972
SymantecBackdoor.Zegost!gen2
ESET-NOD32a variant of Win32/Farfli.HW
APEXMalicious
ClamAVWin.Trojan.Zegost-6725867-0
KasperskyHEUR:Trojan.Win32.Farfli.gen
BitDefenderTrojan.GenericKDZ.94869
NANO-AntivirusTrojan.Win32.Scar.cumxcc
SUPERAntiSpywareTrojan.Agent/Gen-Zegost
AvastWin32:Dropper-JQQ [Drp]
TencentTrojan.Win32.Lebag.b
TACHYONTrojan/W32.Agent.196608.ALQ
SophosTroj/Zegost-BW
F-SecureBackdoor.BDS/Zegost.birna
DrWebTrojan.SpyBot.324
ZillyaBackdoor.PcClient.Win32.20174
TrendMicroBKDR_ZEGOST.SM34
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.94869 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKDZ.94869
JiangminTrojan/Dialer.mav
GoogleDetected
AviraBDS/Zegost.birna
Antiy-AVLTrojan/Win32.PEF13F.ahy
XcitiumTrojWare.Win32.Agent.PDSB@4q3i1w
ArcabitTrojan.Generic.D17295
ViRobotTrojan.Win32.Zegost.Gen.A
ZoneAlarmHEUR:Trojan.Win32.Farfli.gen
MicrosoftTrojan:Win32/Vindor!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dialer.R21927
McAfeeBackDoor-EMA.gen.e
MAXmalware (ai score=100)
VBA32SScope.Trojan.SvcHorse.01643
Cylanceunsafe
ZonerTrojan.Win32.22067
TrendMicro-HouseCallBKDR_ZEGOST.SM34
RisingTrojan.Win32.Lebag.b (CLASSIC)
YandexTrojan.GenAsa!+hGyvTXHWU4
IkarusTrojan.Win32.Dialer
MaxSecureTrojan.Malware.9555056.susgen
FortinetW32/Farfli.BWG!tr
BitDefenderThetaAI:Packer.5C94B99220
AVGWin32:Dropper-JQQ [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.928331009?

Malware.AI.928331009 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment