Malware

Malware.AI.1228146431 (file analysis)

Malware Removal

The Malware.AI.1228146431 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1228146431 virus can do?

  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Anomalous binary characteristics

How to determine Malware.AI.1228146431?


File Info:

name: FCED762CF5031F036DAE.mlw
path: /opt/CAPEv2/storage/binaries/3e83c446ca1620694f1bc339d5f43461abc6d19720395f68a628bdf0c4c7c49b
crc32: A755E6AE
md5: fced762cf5031f036dae234551322f9e
sha1: 9b2e70610f1b7d21ad5c48c136e0b7bce49e4f3c
sha256: 3e83c446ca1620694f1bc339d5f43461abc6d19720395f68a628bdf0c4c7c49b
sha512: 765e6a404f9550bd6bd7caf6eb18dfd9fef4677af41eae6c2ce99689343995b3f8bb58809ea329b57c76de81db3529632fa7ed8f66a66102a89d9085b0d9765a
ssdeep: 6144:H+fABtVrjOSRmcmJmLbR9JWJWTJYJngmmSm51r:HOABtV3OSRmWRvEIYhgmmJX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111447B1937888F02DB5D4FF505B7611A02B0CB9F5B07F36B1CC5B8E81B2B6A25B066D6
sha3_384: b57ef105eff3dee914e9d7a007c9300c39bdd086f3dc2e24d897b81ba63f4d6d17bfb3e8e80d19ea45482e5392ed9fc8
timestamp: 2015-07-11 09:40:22

Version Info:

0: [No Data]

Malware.AI.1228146431 also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.99630
FireEyeGeneric.mg.fced762cf5031f03
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Zusy.99630
CylanceUnsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.cf5031
VirITTrojan.Win32.DownLoader14.CVEZ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.ABP
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.99630
AvastMSIL:Injector-LY [Trj]
Ad-AwareGen:Variant.Zusy.99630
SophosGeneric ML PUA (PUA)
ComodoHeur.Corrupt.PE@1z141z3
DrWebTrojan.DownLoader14.49477
VIPREGen:Variant.Zusy.99630
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.99630 (B)
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan.Injector.HD
AviraHEUR/AGEN.1222284
MicrosoftBackdoor:Win32/Bladabindi!ml
GoogleDetected
AhnLab-V3Malware/Win32.Generic.R159039
Acronissuspicious
MAXmalware (ai score=82)
MalwarebytesMalware.AI.1228146431
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:ZaeR4+35BAcF7DBIsshupQ)
IkarusTrojan.Luminrat
MaxSecureTrojan.Malware.300983.susgen
AVGMSIL:Injector-LY [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.1228146431?

Malware.AI.1228146431 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment