Malware

How to remove “Malware.AI.966031161”?

Malware Removal

The Malware.AI.966031161 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.966031161 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.966031161?


File Info:

name: DE1F35E72D8AEF241300.mlw
path: /opt/CAPEv2/storage/binaries/140abcd375dd2826f4914bac5ca379f138759a61ecc871e0f76c89bc8db295c4
crc32: 6ED51AFE
md5: de1f35e72d8aef241300f3b6a94a5979
sha1: 77f3ec8638638f3485cdc667fbbe4bff40bf7197
sha256: 140abcd375dd2826f4914bac5ca379f138759a61ecc871e0f76c89bc8db295c4
sha512: 386f71bf5912e03d9fc8b39612a0dd303f90db3c0d195356ef83c83cd253aee516a13541fb60244d62503cf56f31bed450919d1ec0b475d7db1fb3107749cfdb
ssdeep: 24576:u62LjVzqKQr7LiWH9Jr2UT1gVat0c5qQTskk:u6KFVQrqWH9wUT14aB5qQTbk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164558C1177E58036F2B32B30697D9224597ABC729C3A890F73C8666D5F70A928D30B77
sha3_384: d64a46e14bc89e795295eeeea239eb9632958d513f9a3b88081fee2aa654c41726dc6f15000d1601a71e1c0d5030c15d
ep_bytes: e8d6060000e97afeffff558bec6aff68
timestamp: 2020-12-09 08:11:10

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java Update Checker
FileVersion: 2.8.281.9
Full Version: 2.8.281.9
InternalName: Java Update Checker
LegalCopyright: Copyright © 2020
OriginalFilename: jucheck.exe
ProductName: Java Platform SE Auto Updater
ProductVersion: 2.8.281.9
Translation: 0x0409 0x04b0

Malware.AI.966031161 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.63197
MalwarebytesMalware.AI.966031161
VIPREGen:Variant.Doina.63197
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ab4bf1 )
K7GWTrojan ( 005ab4bf1 )
CyrenW32/Patched.GQ1.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Patched.NKM
APEXMalicious
KasperskyHEUR:Trojan.Win32.Patched.gen
BitDefenderGen:Variant.Doina.63197
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
TencentMalware.Win32.Gencirc.11b6d08c
DrWebWin32.Beetle.2
ZillyaTrojan.Patched.Win32.159837
McAfee-GW-EditionBehavesLike.Win32.Sality.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.de1f35e72d8aef24
EmsisoftGen:Variant.Doina.63197 (B)
IkarusTrojan.Win32.Krypt
JiangminBackdoor.Convagent.ki
GoogleDetected
Antiy-AVLTrojan/Win32.Patched
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Doina.DF6DD
ZoneAlarmHEUR:Trojan.Win32.Patched.gen
GDataGen:Variant.Doina.63197
AhnLab-V3Malware/Win.Generic.R603657
BitDefenderThetaGen:NN.ZexaF.36738.qv0@aOJ3RHcP
ALYacGen:Variant.Doina.63197
MAXmalware (ai score=80)
VBA32BScope.TrojanDownloader.Emotet
Cylanceunsafe
FortinetW32/Patched.IP!tr
DeepInstinctMALICIOUS

How to remove Malware.AI.966031161?

Malware.AI.966031161 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment