Malware

Malware.AI.1294031746 removal tips

Malware Removal

The Malware.AI.1294031746 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1294031746 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

Related domains:

wpad.local-net

How to determine Malware.AI.1294031746?


File Info:

name: 6FB3D63F8D54E4B35F9F.mlw
path: /opt/CAPEv2/storage/binaries/ca0fcabcc681d41d18227a0917deda9a5211dfec777c94e877e5ea039d7c53ce
crc32: 9263C66A
md5: 6fb3d63f8d54e4b35f9f2612dc04e62b
sha1: 53a15dae35eafd3c7965a4bca6d2c3c789c4bb3b
sha256: ca0fcabcc681d41d18227a0917deda9a5211dfec777c94e877e5ea039d7c53ce
sha512: 074e1aed6e8cab72d1c34ce586ceec2bb11466c933bea56e5d9fd511dd464264c4a24d4f58aecd640d01f2c4b9d3a16c39b1693b4f0fdea8c7ef58f1c875f721
ssdeep: 24576:WYkrD0sWwLzQeRWeCKNLeTThbx9RwY62yB1IUYUBsjkbeAvmTKXqsL074by1okXI:NkrDl1LzQlOQYu9ypn7BBbdLzQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193759D7D7BB88D3ED8BF1B34A2A011222670E5966716EF1E501644DC29C3BF29D163E3
sha3_384: da583693e118a1424d5c32a4831d969a91497730d9eb467f616202d127290183d791e68374e647df988371cece6ed4c2
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-22 21:41:58

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: FenixZone
FileDescription: FenixZoneDownloader
FileVersion: 1.0.0.0
InternalName: FenixZone Downloader.exe
LegalCopyright: Copyright © FenixZone 2017
LegalTrademarks:
OriginalFilename: FenixZone Downloader.exe
ProductName: FenixZoneDownloader
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.1294031746 also known as:

LionicTrojan.Win32.Lazy.4!c
MicroWorld-eScanGen:Variant.Lazy.59113
ALYacGen:Variant.Lazy.59113
CylanceUnsafe
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H0CL221
Paloaltogeneric.ml
BitDefenderGen:Variant.Lazy.59113
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Lazy.59113
SophosMal/Generic-R
McAfee-GW-EditionArtemis
FireEyeGen:Variant.Lazy.59113
EmsisoftGen:Variant.Lazy.59113 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Lazy.59113
AviraTR/Dropper.MSIL.Gen2
MAXmalware (ai score=84)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Lazy.DE6E9
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 99)
McAfeeArtemis!6FB3D63F8D54
MalwarebytesMalware.AI.1294031746
APEXMalicious
IkarusTrojan.Dropper
MaxSecureTrojan.Malware.300983.susgen
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen

How to remove Malware.AI.1294031746?

Malware.AI.1294031746 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment