Malware

Malware.AI.1229377029 malicious file

Malware Removal

The Malware.AI.1229377029 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1229377029 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk

How to determine Malware.AI.1229377029?


File Info:

name: F1C2092FC319C298CDD7.mlw
path: /opt/CAPEv2/storage/binaries/af16a024e90cf9350843190d4563de760f0f2ab2aeeea530aeb301660ca05306
crc32: A5BD20B6
md5: f1c2092fc319c298cdd7dfe797a268b1
sha1: 262e17dd4ac5577918b07d0602a6861af69b1428
sha256: af16a024e90cf9350843190d4563de760f0f2ab2aeeea530aeb301660ca05306
sha512: af82461134ec968eddae9c549bf1d1eba8473bbf8013a438d8f36834a0f61f862c8946247e993422f2f67a3e7d7b21ef6df5f4e5e2149198bf5e6a5123261634
ssdeep: 49152:MiEoBMbVjSOt3hhlQUn6CfPKNDsCakfhPRRdCvExz36NwN7JrZX+QR:Miib9VhQU6j7Rqv9NwVJFOg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CCF5334288554CF7E403E87779CD9C45C996AE85FE6E49B86BCD0F99037B3020D8EA63
sha3_384: 1c57219482f08fd5fdd7608394d74b7a1d66963df0b9f4db30ca1f617f9b8429bbe99fab8db9f2d8aa3f290f51517581
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: FittyFiles Pro
FileVersion: 1.0.0.7
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Malware.AI.1229377029 also known as:

MicroWorld-eScanGen:Variant.Cerbu.151233
FireEyeGen:Variant.Cerbu.151233
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
ClamAVWin.Trojan.Trojanx-9964504-0
KasperskyTrojan.Win32.Ekstak.ampzz
BitDefenderGen:Variant.Cerbu.151233
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Cerbu.151233
EmsisoftGen:Variant.Cerbu.151233 (B)
McAfee-GW-EditionArtemis
GDataWin32.Backdoor.Bodelph.H662CU
JiangminTrojan.Ekstak.cazb
AviraTR/Drop.Agent.zflvx
MAXmalware (ai score=82)
ZoneAlarmTrojan.Win32.Ekstak.ampzz
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Adware/Win.DownloadAssistant.C5226502
McAfeeArtemis!F1C2092FC319
MalwarebytesMalware.AI.1229377029
AVGWin32:TrojanX-gen [Trj]

How to remove Malware.AI.1229377029?

Malware.AI.1229377029 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment