Malware

Malware.AI.115364581 (file analysis)

Malware Removal

The Malware.AI.115364581 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.115364581 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Malware.AI.115364581?


File Info:

name: 9B0667CB0DAF9640DECA.mlw
path: /opt/CAPEv2/storage/binaries/7c849a501a5aa30064bb467c1d4f96271190ff7db84dd564e44c10ed24022fff
crc32: 91C5C990
md5: 9b0667cb0daf9640decad934b924979f
sha1: 382f1ad7821fcfbd42ee1e4dac9ec5199fd06f21
sha256: 7c849a501a5aa30064bb467c1d4f96271190ff7db84dd564e44c10ed24022fff
sha512: c8c8b11cccc3f1189d405e7c26959590e5e8702182ef0a275dfccec84cd925aa08b40511e870f70cbe5faed6dcbd7f48f79394c2b63c456197ec1cbd86a62c96
ssdeep: 3072:dhJ3yRnc6kjJcsJU00QWI9kt5vbcyGzd54xt7EM8E45GWC1/mLH3rKUzwieOIZ:/J3y+6kjJNh3k3QzgxP+5GWC1eLHmU8b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE04AEE28557A4CCF216437DBD04C3124D569D6BE6D097C0B8B51F8C87A642F8B2BE1E
sha3_384: 75a92e797272547faade6db34bdb26793c6c8fcede57a899161ae80180e9af73159e01a6b2b906c060643ed12bd40c97
ep_bytes: 6a40680010000068a08601006a00ff15
timestamp: 2012-09-05 20:26:28

Version Info:

0: [No Data]

Malware.AI.115364581 also known as:

BkavW32.AIDetect.malware1
LionicWorm.Win32.AutoRun.o!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Downloader.126
FireEyeGeneric.mg.9b0667cb0daf9640
McAfeeGenericRXHX-KA!9B0667CB0DAF
MalwarebytesMalware.AI.115364581
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0052ca6a1 )
BitDefenderGen:Variant.Downloader.126
K7GWEmailWorm ( 0052ca6a1 )
CyrenW32/Kryptik.AJG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.Agent.AFG
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Worm.Win32.AutoRun.pef
RisingWorm.Autorun!1.AFBF (CLASSIC)
Ad-AwareGen:Variant.Downloader.126
SophosML/PE-A + Troj/Agent-BCGS
DrWebWin32.HLLW.Autoruner3.499
ZillyaWorm.AutoRun.Win32.192444
TrendMicroTROJ_GEN.R002C0PL321
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
EmsisoftGen:Variant.Downloader.126 (B)
IkarusVirus.Win32.Heur
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASBOL.C6BE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Downloader.126
GDataWin32.Trojan.PSE.T0QFSA
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R295338
Acronissuspicious
BitDefenderThetaAI:Packer.10D9AA541E
ALYacGen:Variant.Downloader.126
VBA32BScope.Worm.Autorun
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PL321
TencentWin32.Worm.Autorun.Hssc
YandexTrojan.GenAsa!6D0EeHKQIts
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.AFG!tr
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.115364581?

Malware.AI.115364581 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment