Malware

About “Malware.AI.1260449034” infection

Malware Removal

The Malware.AI.1260449034 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1260449034 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1260449034?


File Info:

name: 75761B4B734CEACDAA0D.mlw
path: /opt/CAPEv2/storage/binaries/df9cff1ee768cd585ed3e8cef7af761597c4517730544b4b8a507173201721cc
crc32: F4A58E54
md5: 75761b4b734ceacdaa0dd9079e291d09
sha1: 59464e5475bcc03f8318906b56cc45e6b539ef75
sha256: df9cff1ee768cd585ed3e8cef7af761597c4517730544b4b8a507173201721cc
sha512: 6d011a6530f4482eb29e0382cc2e56feadffe7eded2449d7ecff669c2ee793fe74f0afc5ffcadf38d960fa2e6f6c6c6c5e9622c6e139d957090e693712c6e5fc
ssdeep: 24576:DwJte0YmFQURY1h+2oOOpduPKwqeiJSEjVedRqauU9v/FbfPe5K7R:R0YmO3ywISld++pPeI7R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15745D01276D2C033E1A200B15578AB726DBEBD350B3149DB57C81A6D4A35AC16F3AB3F
sha3_384: cb92c74cbe40d9ac6ba51e95eaa65806e4c27e506281f5ff308f8de54a9132c5cf8e419b5511dd045e13e28505a8ec1d
ep_bytes: e8a70f0000e97afeffff558bec6a00ff
timestamp: 2020-02-27 13:37:29

Version Info:

0: [No Data]

Malware.AI.1260449034 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.386558
FireEyeGeneric.mg.75761b4b734ceacd
ZillyaBackdoor.Convagent.Win32.6828
K7AntiVirusTrojan ( 005ab4bf1 )
K7GWTrojan ( 005ab4bf1 )
BitDefenderThetaGen:NN.ZexaF.36738.mvW@aaex5Uhi
CyrenW32/Convagent.DJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Patched.NKM
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Convagent.gen
BitDefenderGen:Variant.Lazy.386558
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10bf216c
EmsisoftGen:Variant.Lazy.386558 (B)
VIPREGen:Variant.Lazy.386558
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminesuspicious.low.ml.score
SophosML/PE-A
IkarusTrojan.Win32.Patched
GDataGen:Variant.Lazy.386558
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.GenKryptik
ArcabitTrojan.Lazy.D5E5FE
ZoneAlarmHEUR:Trojan.Win32.Patched.gen
MicrosoftTrojan:Win32/Convagent.AJ!MTB
GoogleDetected
VBA32BScope.Trojan.Meterpreter
ALYacGen:Variant.Lazy.386558
MalwarebytesMalware.AI.1260449034
RisingTrojan.Generic@AI.100 (RDML:DGWr+H5/UjwhkJdHFwvpOQ)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Patched.IP!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.1260449034?

Malware.AI.1260449034 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment