Malware

Malware.AI.1235265714 removal

Malware Removal

The Malware.AI.1235265714 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1235265714 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.1235265714?


File Info:

name: CDBA30FC3FC5A8ED0CFF.mlw
path: /opt/CAPEv2/storage/binaries/17133b9a62ec1529485a82fb20883dc2e118d57b3f521c742e1b9393c7e292bf
crc32: A4190781
md5: cdba30fc3fc5a8ed0cff947a5677d44e
sha1: 64da440eb6fe090dc7df9c3c1d4c1ec813619fb5
sha256: 17133b9a62ec1529485a82fb20883dc2e118d57b3f521c742e1b9393c7e292bf
sha512: ef237b6daf2a3b1af26dc4802b30d4f34d67b0ab6911d072bb41d7cc295268d0a8d8c5bda850d1cce2019ae5f56c5ba5fdc9bb8ad8f79a7bb0cc77862cceb07c
ssdeep: 12288:BOiU4ueHwfNPZzXzES8pv0WKR/ElaEyNvMMUuhcpGillDB2lEU:BOiUJeQl5DES8pvjmMQEy4JAlE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123C45B23D20689B0E258243174B66BBA5F39EFA31D61D697E380FDF81F36231DA5610D
sha3_384: 98cc65316e08a0c5c6cc036c2bb2bfac73f9b1545998fd772c38b5dd4be84b427beac031c8265b1e0db1179bcd28a25b
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2020-05-05 02:13:11

Version Info:

FileVersion: 3.2.0.5
FileDescription: 图吧工具箱2020主程序
ProductName: 图吧工具箱
ProductVersion: 3.2.0.5
CompanyName: Sunlight Studio
LegalCopyright: Copyright Sunlight Studio . All rights reserved.
Comments: 官网:http://www.tbtool.cn
Translation: 0x0804 0x04b0

Malware.AI.1235265714 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.cdba30fc3fc5a8ed
Cylanceunsafe
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/GenKryptik.875c13d0
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/GenKryptik.GCRM
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Malware-gen
TencentWin32.Trojan.Kryptik.Njgl
F-SecureTrojan.TR/Kryptik.trgky
TrendMicroTROJ_GEN.R002C0PH823
McAfee-GW-EditionRDN/Generic.dx
SophosMal/EncPk-ADE
SentinelOneStatic AI – Malicious PE
AviraTR/Kryptik.trgky
Antiy-AVLTrojan/Win32.FlyStudio.a
ViRobotTrojan.Win.Z.Wacatac.580608.A
GDataWin32.Trojan.PSE.1KQMTX4
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5328934
McAfeeRDN/Generic.dx
MalwarebytesMalware.AI.1235265714
TrendMicro-HouseCallTROJ_GEN.R002C0PH823
RisingTrojan.Astaroth!8.11168 (TFE:1:xKwRXf2ID5B)
IkarusTrojan.Win32.Krypt
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Malware.AI.1235265714?

Malware.AI.1235265714 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment