Malware

About “Malware.AI.1128043376” infection

Malware Removal

The Malware.AI.1128043376 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1128043376 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1128043376?


File Info:

name: 8B8D2C3861902B72E3DA.mlw
path: /opt/CAPEv2/storage/binaries/239fd6275026ee192549c421a7b59f1b209873ae70cef234ec2274619d80917d
crc32: 9463145F
md5: 8b8d2c3861902b72e3da485fddb611b4
sha1: 59076663fddfdb2faaa5e5d51ff7563acd708526
sha256: 239fd6275026ee192549c421a7b59f1b209873ae70cef234ec2274619d80917d
sha512: a5370083b6f1fcf84dced0785537a1d292aaad3cdae8d55da613cb69364a35cf4637bcbc547cb7be9dbc1b31d1fed8d990873d7ed66227ca844b95dac1c1caa3
ssdeep: 3072:fOjVYvijQdrgUDdCGAX31X7tlcxEHglJsd1/Ab32yZlOsQqO1j99Mop:icdlcX31X7tlMGFTy6sQvJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17144FE7F6E4140E4D05490F3EE9BEB9D21F22825CB33A8D65F101B548867D5FAA3868F
sha3_384: a7d03d8abb68bb039e5b1c04f222d219ab38d43be619ffe0e4dd1db9fdd7f1e4e583e9ba5ad74144f51f381eb0e98652
ep_bytes: 6834134000e8f0ffffff000000000000
timestamp: 2003-08-26 18:54:58

Version Info:

0: [No Data]

Malware.AI.1128043376 also known as:

BkavW32.AIDetectMalware
DrWebWin32.HLLW.Autoruner1.15681
MicroWorld-eScanGen:Variant.Cerbu.167078
FireEyeGeneric.mg.8b8d2c3861902b72
CAT-QuickHealTrojan.Beebone.D
ALYacGen:Variant.Cerbu.167078
Cylanceunsafe
VIPREGen:Variant.Cerbu.167078
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.861902
BitDefenderThetaGen:NN.ZevbaF.36196.pmX@aWcMtjm
VirITTrojan.Win32.VBCrypt.ETW
CyrenW32/Vobfus.O.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.AS
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jorik.Vobfus.cqaz
BitDefenderGen:Variant.Cerbu.167078
NANO-AntivirusTrojan.Win32.Jorik.crgjcy
AvastWin32:Pronny-I [Trj]
RisingWorm.Pronny!1.E3EA (CLASSIC)
SophosW32/Vobfus-AH
F-SecureTrojan.TR/Patched.Ren.Gen
BaiduWin32.Worm.Pronny.gn
TrendMicroWORM_VOBFUS.SMDF1
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dm
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Cerbu.167078 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10T9JN3
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.Cerbu.D28CA6
ViRobotTrojan.Win32.Jorik.245760.D
ZoneAlarmTrojan.Win32.Jorik.Vobfus.cqaz
MicrosoftWorm:Win32/Vobfus.EZ
GoogleDetected
Acronissuspicious
McAfeeVBObfus.dv
TACHYONTrojan/W32.VB-Jorik.253952.E
VBA32Trojan.Vobfus
MalwarebytesMalware.AI.1128043376
PandaGeneric Malware
TrendMicro-HouseCallWORM_VOBFUS.SMDF1
TencentTrojan.Win32.Jorik.hj
YandexTrojan.GenAsa!HkTYGOaejjo
IkarusTrojan.Win32.Jorik
MaxSecureTrojan.Win32.Jorik.Vobfus.cqaz
FortinetW32/Jorik.EGLG!tr
AVGWin32:Pronny-I [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.1128043376?

Malware.AI.1128043376 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment