Malware

Malware.AI.1239001364 malicious file

Malware Removal

The Malware.AI.1239001364 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1239001364 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.1239001364?


File Info:

name: 5A881E1E6F4487368721.mlw
path: /opt/CAPEv2/storage/binaries/16262db338386314fabe3acb310f44140568ce0f96d3fd28607bae1e60bfda09
crc32: 3B390830
md5: 5a881e1e6f4487368721199381a06638
sha1: 8546475b64feaddae5ec48e82afa8bd0b620aaaf
sha256: 16262db338386314fabe3acb310f44140568ce0f96d3fd28607bae1e60bfda09
sha512: 60f869a39566db118de421b33ef5af853a87a3950bb2a040183884f4c3ff2e774057b7f9ed20a35ed00a5b46f081c3814ef515ded16f4a93576102c25e7bb144
ssdeep: 24576:rAG7y6dHFMcaSjWUBXHTgm/rq6FIurs7rW6qKP12E:VD9BXTgm/W6FjsHBgE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11145AE0273E0D032D0B312705A7D97A18FB6BCA05B71C68F63D46A6D5E72AC0CA76767
sha3_384: 4d78f05ebd5013e9620de0af5bfbca3189214921283a0a4d8da0ac30e6906ea021b9729ebe3489b4feb64a277de33e50
ep_bytes: 60be003066008dbe00e0d9ff5783cdff
timestamp: 2016-04-18 13:39:48

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Malware.AI.1239001364 also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.434668
FireEyeGeneric.mg.5a881e1e6f448736
McAfeeArtemis!5A881E1E6F44
CylanceUnsafe
VIPREGen:Variant.Zusy.434668
SangforVirus_Suspicious.Win32.Sality.bh
Cybereasonmalicious.e6f448
VirITWin32.Sality.BH
CyrenW32/Sality.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win64/HackKMS.I potentially unsafe
APEXMalicious
BitDefenderGen:Variant.Zusy.434668
SUPERAntiSpywareTrojan.Agent/Gen-HackMS
AvastWin32:Malware-gen
TencentHacktool.Win64.Kmsauto.16000428
Ad-AwareGen:Variant.Zusy.434668
EmsisoftGen:Variant.Zusy.434668 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.KMSAuto.Win32.107
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.th
Trapminemalicious.high.ml.score
SophosMal/SwiftG-X
SentinelOneStatic AI – Malicious PE
JiangminWin32/HLLP.Kuku.poly2
AviraHEUR/AGEN.1204519
Antiy-AVLTrojan/Generic.ASBOL.2F4B
MicrosoftHackTool:Win32/AutoKMS
GDataGen:Variant.Zusy.434668
CynetMalicious (score: 100)
AhnLab-V3HackTool/Win32.AutoKMS.R182872
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34582.hn0@a4el2Mlj
ALYacGen:Variant.Zusy.434668
MAXmalware (ai score=80)
MalwarebytesMalware.AI.1239001364
RisingVirus.Sality/Debris!1.A12C (CLASSIC)
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ULPM.16C0!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.1239001364?

Malware.AI.1239001364 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment