Malware

Malware.AI.13065858 removal instruction

Malware Removal

The Malware.AI.13065858 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.13065858 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Malware.AI.13065858?


File Info:

name: A948D1EBD6F30FF9D368.mlw
path: /opt/CAPEv2/storage/binaries/5b25169b2a50590dd23ef81164278c79533978cbeb2a79127318ac454a639aa9
crc32: 7B38F4E4
md5: a948d1ebd6f30ff9d368994ba48415e8
sha1: 956efa38ad04ddbd369cff0248d0db54ac851463
sha256: 5b25169b2a50590dd23ef81164278c79533978cbeb2a79127318ac454a639aa9
sha512: 9b702b4426937a886e300c5425584e0983a57de9bde59ab570a045c1bdc11ed58fa0b9be5362a560bb044d469aaac7438968efede323c15e57160597286dafd7
ssdeep: 96:J6JbC4clhXEpEbvQcZAIKrmsqC8KpenHy7hhlhfcTOSIek:JwenvOHfqC8K8nHyJhXSC
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FAD1920A57DD437BD8BA4B7C68B303035378E4556E23EB1E0DC8026E68A4B458F32BD9
sha3_384: 6da9c4c4549f5b9a7b2e752b48b19515e70a80cde14dba4d11c2b8ade69b0ffd378f52d1d521d96efacd7b203b6995f3
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-07-19 01:54:01

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: cspsvc.exe
LegalCopyright:
OriginalFilename: cspsvc.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Malware.AI.13065858 also known as:

MicroWorld-eScanIL:Trojan.MSILZilla.6646
FireEyeIL:Trojan.MSILZilla.6646
McAfeeGenericRXFX-YM!A948D1EBD6F3
ZillyaTrojan.Miner.Win32.3678
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00534cc31 )
K7GWTrojan ( 00534cc31 )
Cybereasonmalicious.bd6f30
CyrenW32/Trojan.CBH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.SPP
APEXMalicious
ClamAVWin.Trojan.Johnnie-9830068-0
KasperskyHEUR:Trojan.MSIL.Miner.gen
BitDefenderIL:Trojan.MSILZilla.6646
NANO-AntivirusTrojan.Win32.Miner.jqhegj
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Msil.Miner.pb
Ad-AwareIL:Trojan.MSILZilla.6646
SophosML/PE-A
ComodoTrojWare.MSIL.Miner.GU@8ghwjr
DrWebTrojan.Starter.7713
VIPREIL:Trojan.MSILZilla.6646
TrendMicroTrojan.MSIL.SERVSTAR.SMAA
McAfee-GW-EditionGenericRXFX-YM!A948D1EBD6F3
Trapminesuspicious.low.ml.score
EmsisoftIL:Trojan.MSILZilla.6646 (B)
IkarusTrojan.MSIL.Agent
GDataIL:Trojan.MSILZilla.6646
AviraHEUR/AGEN.1208692
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C2671981
BitDefenderThetaGen:NN.ZemsilF.34806.am0@aed0Otn
ALYacIL:Trojan.MSILZilla.6646
MalwarebytesMalware.AI.13065858
RisingTrojan.CspMiner!1.C2FE (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinMiner.SPP!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.13065858?

Malware.AI.13065858 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment