Malware

Malware.AI.1213980210 removal

Malware Removal

The Malware.AI.1213980210 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1213980210 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1213980210?


File Info:

name: CFE284799BC63B11FAD2.mlw
path: /opt/CAPEv2/storage/binaries/5f0c7594ab36f77fb2de3bc5c5b91440cce6c4841119963a1e80225280b00fd6
crc32: 7D74C8C8
md5: cfe284799bc63b11fad2f47eadf603c2
sha1: 0e9f0d0679e7030caa1bbe81806b8aad9318fa32
sha256: 5f0c7594ab36f77fb2de3bc5c5b91440cce6c4841119963a1e80225280b00fd6
sha512: 126b7687da0a3a385e80d48936c2d62b2fefb50d0fe466d632bbb33b9714ad7ec7c03045f8525dfde7cdf0f30414f9ee46a15a6a5e94a6f4f53768cb53034dfd
ssdeep: 3072:wnEOti99xNKk62zI3W0u1EkIeIXxX48r788L3avt5yylKZnhAmfc8tT:it+frI3xfrw8LqV5yMKlhAmfh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E4447D1073D81D71C792013BAAF66D5962EABC630330807974ED36B767B244AC97B7B8
sha3_384: 52c4e5c2e4c23e2ee4a1072f28ece90267e3ddc8bbef1f16849ad540bf9c4c56771669900af7a97ccfc6fd51c9e171a7
ep_bytes: e80060000073ebebebeb73237dabebf3
timestamp: 2010-08-01 10:32:37

Version Info:

0: [No Data]

Malware.AI.1213980210 also known as:

BkavW32.OverlayND.PE
LionicHacktool.Win32.Krap.3!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Agent.EXMP
ClamAVWin.Trojan.Agent-6943819-1
FireEyeGeneric.mg.cfe284799bc63b11
CAT-QuickHealTrojan.Ausiv.S12202810
McAfeePacked-SU!CFE284799BC6
Cylanceunsafe
VIPRETrojan.Agent.EXMP
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00517a0d1 )
AlibabaVirus:Win32/Ausiv.1225
K7GWTrojan ( 00517a0d1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Ausiv.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Ausiv.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyPacked.Win32.Krap.jc
BitDefenderTrojan.Agent.EXMP
NANO-AntivirusTrojan.Win32.Krap.espnuv
AvastWin32:Agent-BCFZ [Trj]
TencentTrojan.Win32.Kryptik.fwwy
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.KillFiles.62112
TrendMicroTROJ_GEN.R03BC0DD623
McAfee-GW-EditionBehavesLike.Win32.Sivis.dh
Trapminemalicious.high.ml.score
EmsisoftTrojan.Agent.EXMP (B)
IkarusGen.Win32.FileInfector
GDataWin32.Virus.Ausiv.B
JiangminPacked.Krap.fyig
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLVirus/Win32.Expiro.imp
XcitiumVirus.Win32.VirLock.GA@7lv9go
ArcabitTrojan.Agent.EXMP
ViRobotTrojan.Win32.Agent.Gen.C
ZoneAlarmPacked.Win32.Krap.jc
MicrosoftTrojan:Win32/Ausiv
GoogleDetected
AhnLab-V3Packed/Win.Krap.C5402802
ALYacTrojan.Agent.EXMP
VBA32Malware-Cryptor.General.3
MalwarebytesMalware.AI.1213980210
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DD623
RisingVirus.Sivis!1.A647 (CLASSIC)
YandexTrojan.GenAsa!8BX67dEhxck
SentinelOneStatic AI – Malicious PE
MaxSecurePacked.Krap.JC
FortinetW32/Ausiv.A
BitDefenderThetaAI:Packer.BE1F2A271F
AVGWin32:Agent-BCFZ [Trj]
Cybereasonmalicious.99bc63
DeepInstinctMALICIOUS

How to remove Malware.AI.1213980210?

Malware.AI.1213980210 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment