Malware

Malware.AI.1289050411 removal instruction

Malware Removal

The Malware.AI.1289050411 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1289050411 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.1289050411?


File Info:

name: 18BA335D49BDF75E4A7D.mlw
path: /opt/CAPEv2/storage/binaries/e549a4a6ad7a9b7419e6b7530333b6e8e2cfee26a4ca276a23bff9db79875cf6
crc32: D015C68E
md5: 18ba335d49bdf75e4a7d5d425420cd54
sha1: 090ec2827505e642a39763d7edc30dca7f20d3b6
sha256: e549a4a6ad7a9b7419e6b7530333b6e8e2cfee26a4ca276a23bff9db79875cf6
sha512: abb2f94a3ea80d32fbfaaf9f48cd9be56681f5f63f03923e4aa35bd6df693ecdde3197ef60ac114b0ca989ee5bf8046cfe219e96f10f8bd74ce377cbbf5d23c7
ssdeep: 24576:fB4g1KC0cdTTFWA+FtYJNrw+hDfZcUxOOjg13v:fSFATToA+h6hlPKv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C2458A95A7E5FFA2DE868CB014425D0E50B12A0FD4776E329A797FC822372D1ED13263
sha3_384: 8f67468fad02af64b4fc42e8b02eb93ffef96a45e15b2193b284ff5d085cce1460f3b2bbe0ed293d77ae8ab35f572cad
ep_bytes: 60be00a058008dbe0070e7ff5783cdff
timestamp: 2019-06-13 09:31:21

Version Info:

Comments:
CompanyName: 刀锋网络
FileDescription: 租号玩推广在线安装包
FileVersion: 5, 5, 326, 1
InternalName: loader
LegalCopyright: Copyright © daofeng. All Rights Reserved.
OriginalFilename: loader.exe
ProductName: zuhaowan
ProductVersion: 5, 5, 326, 1
Translation: 0x0804 0x04b0

Malware.AI.1289050411 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.47528019
FireEyeTrojan.GenericKD.47528019
McAfeeGenericRXPN-AI!18BA335D49BD
CylanceUnsafe
ZillyaTool.Zuhaowan.Win32.1
K7AntiVirusRiskware ( 00585d941 )
K7GWRiskware ( 00585d941 )
Cybereasonmalicious.27505e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.Zuhaowan.A
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.47528019
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.11ce8321
Ad-AwareTrojan.GenericKD.47528019
EmsisoftTrojan.GenericKD.47528019 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PL421
McAfee-GW-EditionBehavesLike.Win32.HLLP.tc
SophosMal/Generic-S
GDataTrojan.GenericKD.47528019
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.R434687
BitDefenderThetaGen:NN.ZexaCO.34084.lnMfaO2@a7hj
ALYacTrojan.GenericKD.47528019
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wofith
MalwarebytesMalware.AI.1289050411
TrendMicro-HouseCallTROJ_GEN.R002C0PL421
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Zuhaowan
AVGWin32:TrojanX-gen [Trj]
PandaTrj/CI.A

How to remove Malware.AI.1289050411?

Malware.AI.1289050411 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment