Malware

About “Malware.AI.1291878946” infection

Malware Removal

The Malware.AI.1291878946 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1291878946 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Malware.AI.1291878946?


File Info:

name: BDCC8C2E63B19F687DBE.mlw
path: /opt/CAPEv2/storage/binaries/3a372fceceb56d81febdb79477defff84d2db6cc4fa06ae6a390fc8b2835c47b
crc32: 9EFA85CD
md5: bdcc8c2e63b19f687dbe588a404d9afd
sha1: eac693722f74a5976c0a934cc514bf662785116d
sha256: 3a372fceceb56d81febdb79477defff84d2db6cc4fa06ae6a390fc8b2835c47b
sha512: 406044b51cf122f5f1cc5e6c715b4a3b44fd4b0a45c78e476a1a110c0275d8a7c348ffc0cc78391b81e424c907bfe343a4d00036aa6d9cb3164c5c5e48f45056
ssdeep: 49152:7cbwlixlYN0MH6yT395cm0xvDzPL3S+LtD96lOihcpvjx9OlDR0kgTFQiZGV9OS1:7cbwlqYN0MHB7c/xzPL3S+LtDgKvjx9G
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0B58D227A7498B7C1733670591EE3B9B27DFD200A3901B752E04E3B7A615D3A93861F
sha3_384: dc544a35599c12c4136a6b6ab13b204f75a81eb8282430a046cf6dbfe19891297698d77d1f6e515bd4f2036895fb9637
ep_bytes: e81d8d0000e989feffff3b0d60d05b00
timestamp: 2021-02-03 03:03:32

Version Info:

CompanyName: 湖北翰辉企业管理咨询有限公司
FileDescription: zShut
FileVersion: 1, 0, 0, 2
InternalName: 122ttttttttt.exe
LegalCopyright: Copyright (C) 2020-2022
OriginalFilename: zShutB.exe
ProductName: zShut
ProductVersion: 1.1.0.1
Translation: 0x0804 0x04b0

Malware.AI.1291878946 also known as:

LionicTrojan.Win32.AdLoad.a!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.bdcc8c2e63b19f68
CylanceUnsafe
SangforVirus_Suspicious.Win32.Sality.bh
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaAdWare:Win32/Softcnapp.714782a3
K7GWAdware ( 00578df21 )
K7AntiVirusAdware ( 00578df21 )
BitDefenderThetaGen:NN.ZexaF.34638.lw2@a8@dBrhj
VirITWin32.Sality.BI
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Softcnapp.BK potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Downloader.Chindo-9859805-0
KasperskyHEUR:Trojan-Downloader.Win32.AdLoad.gen
NANO-AntivirusTrojan.Win32.AdLoad.iurikt
AvastWin32:Sality [Inf]
TencentPua:AdWare.Win32.Burden.16000058
SophosMal/Generic-S
DrWebTrojan.NtRootKit.20214
ZillyaDownloader.Adload.Win32.139
TrendMicroPE_SALITY.ER
McAfee-GW-EditionBehavesLike.Win32.Virus.vh
IkarusPUA.Softcnapp
JiangminTrojanDownloader.Adload.abzc
AviraTR/Patched.Ren.Gen
ZoneAlarmHEUR:Trojan-Downloader.Win32.AdLoad.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R416680
Acronissuspicious
VBA32BScope.TrojanDownloader.Adload
MalwarebytesMalware.AI.1291878946
TrendMicro-HouseCallPE_SALITY.ER
RisingAdware.Agent!1.CE32 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.6991189.susgen
FortinetRiskware/Softcnapp.BK
AVGWin32:Sality [Inf]

How to remove Malware.AI.1291878946?

Malware.AI.1291878946 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment