Malware

Malware.AI.1040152386 removal guide

Malware Removal

The Malware.AI.1040152386 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1040152386 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid

How to determine Malware.AI.1040152386?


File Info:

name: 2A0B9DB9498E8D3750C4.mlw
path: /opt/CAPEv2/storage/binaries/e48eb2f6e1b443144e6e4f8942863df6ac1396d79fec7781e012374edcee844c
crc32: 54FB0D49
md5: 2a0b9db9498e8d3750c405f779f4a813
sha1: b0a407e35326ebce5e1cc43c96f00e9c9b8b4042
sha256: e48eb2f6e1b443144e6e4f8942863df6ac1396d79fec7781e012374edcee844c
sha512: e751d710a92d25538280dd278a0bcd0ae221b483574d72df8637531aac2a92bca081229d8cab32ab53d7c4b57887c26d53a047cf1c8cd91f14d090e1bb146161
ssdeep: 98304:ljI96ByP08ecFbAIZFTaF0/W/j4V/8HzdhUYBhv3ekFQU:lj9OxAuTaFoS4SdhHBB3emR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16A1633C1BF666AB8C3C58AF17570F363AB2FF94C280ACED7C7509998546AE810D0525F
sha3_384: 9e7bf095109dcb82dcefb5a410179bb8ae4a84cade7b4f618fe2e322dcf71da896f44dbd9d9e36038a6556b1dc31183c
ep_bytes: 81ecd4020000535556576a2033ed5e89
timestamp: 2012-02-24 19:20:04

Version Info:

FileDescription:
FileVersion: 0.0.0
LegalCopyright:
ProductVersion: 0.0.0
Translation: 0x0000 0x04b0

Malware.AI.1040152386 also known as:

LionicTrojan.Win32.Upatre.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Dropper.ZLG
CAT-QuickHealTrojan.Silentinstall
McAfeeArtemis!2A0B9DB9498E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforPUP.Win32.Agent.JJJ
K7AntiVirusTrojan ( 0057107a1 )
AlibabaTrojanDownloader:Win32/Upatre.d607140e
K7GWTrojan ( 0057107a1 )
Cybereasonmalicious.9498e8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.SilentInstallBuilder.A suspicious
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Upatre-9829421-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Dropper.ZLG
NANO-AntivirusRiskware.Win32.SilentInstaller.ichexi
AvastNSIS:BundlerX-gen [PUP]
RisingDownloader.Upatre!8.B5 (CLOUD)
Ad-AwareTrojan.Dropper.ZLG
SophosGeneric ML PUA (PUA)
DrWebTrojan.Siggen10.58399
ZillyaDownloader.Upatre.Win32.69043
TrendMicroTROJ_GEN.R002C0GK721
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
FireEyeGeneric.mg.2a0b9db9498e8d37
EmsisoftTrojan.Dropper.ZLG (B)
GDataTrojan.Dropper.ZLG
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASSuf.3C69E
KingsoftWin32.TrojDownloader.Upatre.iw.(kcloud)
ArcabitTrojan.Dropper.ZLG
MicrosoftTrojanDownloader:Win32/Upatre
AhnLab-V3Trojan/Win32.Wacatac.R353512
ALYacTrojan.Dropper.ZLG
VBA32TrojanDownloader.Upatre
MalwarebytesMalware.AI.1040152386
TrendMicro-HouseCallTROJ_GEN.R002C0GK721
TencentWin32.Trojan-downloader.Upatre.Hpsd
YandexTrojan.DL.Upatre!59VGZ5Y/2Bo
MaxSecureTrojan.Malware.109442060.susgen
FortinetRiskware/Upatre
WebrootW32.Malware.Gen
AVGNSIS:BundlerX-gen [PUP]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1040152386?

Malware.AI.1040152386 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment