Malware

Should I remove “Malware.AI.1125964646”?

Malware Removal

The Malware.AI.1125964646 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1125964646 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Malware.AI.1125964646?


File Info:

name: E95CF2D8BFE461E056AB.mlw
path: /opt/CAPEv2/storage/binaries/a36419171661b03a934816fa390e06043800b76068b2bbf9ee6584c04ab08f46
crc32: 1BE8A25D
md5: e95cf2d8bfe461e056ab9eb922eb9a39
sha1: 0896ae97f249b5b93b9c41745385625bed6b5a3c
sha256: a36419171661b03a934816fa390e06043800b76068b2bbf9ee6584c04ab08f46
sha512: ed5736a9a33d1acc5f3e4c387ef745a40c6650e01638ff1a16ce6d8e0b64d7e0b700689431dcfc0c149819710aa2be44cde7a6547b3e773d7a4cf495755ceba7
ssdeep: 96:DVr6HVN9XcpXnZjxAnQWRIUZ2CmXUMD1qzDk1kx:561HupCQWRIgSXzk/OO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FEC1D6825FD20AE3D37B8F3545F58484BAB9F0236867CE1EF18B03961922386CDA1752
sha3_384: 76c2817987cf2c255a726eb1c37be4eedd1523c8ca782c73ec74606cdd633ee015234c26d2191c1b365d295c3d093b62
ep_bytes: 558bec81ec3808000053565733db53ff
timestamp: 2014-01-22 09:47:42

Version Info:

0: [No Data]

Malware.AI.1125964646 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ppatre.Gen.1
ClamAVWin.Downloader.Upatre-9789941-0
FireEyeGeneric.mg.e95cf2d8bfe461e0
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ppatre.Gen.1
CylanceUnsafe
ZillyaDownloader.SmallGen.Win32.2
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0048f6391 )
K7GWTrojan-Downloader ( 0048f6391 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Upatre.LI.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-Spy.Win32.Zbot.gen
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.jseawh
AvastWin32:Waski-A [Trj]
TencentTrojan.Win32.Waski.b
Ad-AwareTrojan.Ppatre.Gen.1
EmsisoftTrojan.Ppatre.Gen.1 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.AQ@7t0jau
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Downloader.zt
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Mal/EncPk-ACO
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.PSE.10QINFY
JiangminTrojanDownloader.Waski.ao
AviraHEUR/AGEN.1207387
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASCommon.173
ArcabitTrojan.Ppatre.Gen.1
MicrosoftTrojan:Win32/Waski.A!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Upatre.R258184
McAfeeDownloader-FML!E95CF2D8BFE4
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.1125964646
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingTrojan.Generic@AI.100 (RDML:yeJYbzw673LaWlznNcqk/w)
YandexTrojan.GenAsa!EeB+TI3QYUc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.34646.auX@aSTQzFei
AVGWin32:Waski-A [Trj]
Cybereasonmalicious.8bfe46
PandaTrj/Genetic.gen

How to remove Malware.AI.1125964646?

Malware.AI.1125964646 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment