Malware

Malware.AI.1218991074 removal

Malware Removal

The Malware.AI.1218991074 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1218991074 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1218991074?


File Info:

name: F2A791C64136C738C6B5.mlw
path: /opt/CAPEv2/storage/binaries/1dffbd38d4d0a3e4a5461502f8dff9d85f6ba622561162c7c46cad13e390989a
crc32: 33EB2683
md5: f2a791c64136c738c6b54e26d5899796
sha1: e4e548bac213edd20793ef2e64dae09e9de4140e
sha256: 1dffbd38d4d0a3e4a5461502f8dff9d85f6ba622561162c7c46cad13e390989a
sha512: 829ac6bf55f5c64d7930b6f8000064bf195f5e95953d384dcbbedd635ec616c059ff003b029323e59cca58f59c2ed8ed09780bf3efe5d836de7c0121b7b39006
ssdeep: 24576:0A5agxqq5lJWH3gDBo1R0xjOtzzY6l4i30WcrdTystGB6dq9g4T:0APAemIBMeEtzzY62ikWQT7gB6Q9h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12045333359198951C6C12630A57F27308B997C3DA9CD29F4273A3DDBD6FB2124A70E8B
sha3_384: 84167e22db1b942a26a692d31e2f595d18a8a8a4f6882826720035b95996fbaf7b3813e283dca249787a4405afd2997a
ep_bytes: 60be00f004108dbe0020fbffc7879cf0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Malware.AI.1218991074 also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.CPEX-based.x!c
Elasticmalicious (moderate confidence)
DrWebBackDoor.Poison.61
MicroWorld-eScanTrojan.Generic.785023
FireEyeGeneric.mg.f2a791c64136c738
CAT-QuickHealTrojan.Delf.17165
SkyhighBehavesLike.Win32.Generic.tc
ALYacTrojan.Generic.785023
MalwarebytesMalware.AI.1218991074
VIPRETrojan.Generic.785023
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005173e21 )
BitDefenderTrojan.Generic.785023
K7GWTrojan ( 005173e21 )
Cybereasonmalicious.ac213e
BitDefenderThetaGen:NN.ZelphiF.36792.inJfaKJeypbe
VirITTrojan.Win32.Generic.LRU
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Packed.ExeFlasher suspicious
APEXMalicious
ClamAVWin.Packed.Buzus-6981476-0
KasperskyPacked.Win32.CPEX-based.eq
AlibabaVirTool:Win32/CPEX-based.b2d2dd5e
NANO-AntivirusTrojan.Win32.CPEXbased.bejytp
ViRobotTrojan.Win32.Buzus.374868
RisingBackdoor.Win32.MsnBot.b (CLOUD)
SophosMal/Behav-328
F-SecureTrojan.TR/Spy.Ardamax.ckp
ZillyaTrojan.Buzus.Win32.2199
TrendMicroTROJ_FAM_0001199.TOMA
Trapminemalicious.high.ml.score
EmsisoftTrojan.Generic.785023 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Buzus.puv
WebrootW32.Injector.Gen
GoogleDetected
AviraTR/Spy.Ardamax.ckp
VaristW32/DelfInject.A.gen!Eldorado
Antiy-AVLTrojan[Packed]/Win32.CPEX-based
Kingsoftmalware.kb.b.951
MicrosoftProgram:Win32/Wacapew.C!ml
XcitiumTrojWare.Win32.TrojanDropper.Binder.G@nt9lf
ArcabitTrojan.Generic.DBFA7F
ZoneAlarmPacked.Win32.CPEX-based.eq
GDataTrojan.Generic.785023
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Xema.R44960
McAfeePWS-LDPinch.a!hv
DeepInstinctMALICIOUS
VBA32BScope.Binder.Buzus.er
Cylanceunsafe
PandaW32/Buzus.BZ.worm
TrendMicro-HouseCallTROJ_FAM_0001199.TOMA
TencentMalware.Win32.Gencirc.115a267b
IkarusTrojan.Buzus.iij
FortinetW32/DELFINJECT.A!tr
AVGWin32:Dropper-gen [Drp]
AvastWin32:Dropper-gen [Drp]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Malware.AI.1218991074?

Malware.AI.1218991074 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment