Malware

Malware.AI.1320607851 removal tips

Malware Removal

The Malware.AI.1320607851 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1320607851 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.1320607851?


File Info:

name: 88BDC0337C21FDBE80FD.mlw
path: /opt/CAPEv2/storage/binaries/c5ceafd579d43305d51447a107b45f9f22c9a0981f30d17af32a045e97f39694
crc32: 09D36CDF
md5: 88bdc0337c21fdbe80fd4b8fd90f75b2
sha1: 6118c96a082a6dda2800b5e77270263ed82c499e
sha256: c5ceafd579d43305d51447a107b45f9f22c9a0981f30d17af32a045e97f39694
sha512: a7d3b97621898b8d54feeb6cb6e44342351408bc1e2bca43ea3209693dec73dee4b6b2cb8e0b475c3af8eb8b706d4530db7bbdd1418f2b2753927b3062eea5b5
ssdeep: 98304:8p4etmanQsT4wGVP6YNsyU8aCVFP+AIua8kP/RB5CkyZCd3JBAUZLC:IMwGVPuHCFUPtCkyu3JVW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T141968D23F001D452D2191AF126B1563C7A74AE6218B5C993FFECFDB5AF3253283AA50D
sha3_384: ce9102ec7e881f898714f661ba525dcc9c5a01a56ffecf45d3f253ddc8ebb81716f9e1af74a703247e58c7a016b8ed2a
ep_bytes: 558bec6aff685087b5006814a8730064
timestamp: 2022-09-10 12:24:53

Version Info:

FileVersion: 1.0.3.0
FileDescription: HIQQ
ProductName: HIQQ
ProductVersion: 1.0.3.0
CompanyName: 马化腾
LegalCopyright: 协议版权归马总所有
Comments: HIQQ
Translation: 0x0804 0x04b0

Malware.AI.1320607851 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lIa2
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Generic.31777495
ClamAVWin.Malware.Generic-9820446-0
FireEyeGeneric.mg.88bdc0337c21fdbe
ALYacTrojan.Generic.31777495
CylanceUnsafe
VIPRETrojan.Generic.31777495
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.a082a6
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:RiskTool.Win32.FlyStudio.gen
BitDefenderTrojan.Generic.31777495
AvastWin32:TrojanX-gen [Trj]
Ad-AwareTrojan.Generic.31777495
EmsisoftTrojan.Generic.31777495 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
Trapminesuspicious.low.ml.score
SophosGeneric PUA GB (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1R38QWG
JiangminTrojan/Agent.fbbo
Antiy-AVLTrojan/Generic.ASCommon.FA
ArcabitTrojan.Generic.D1E4E2D7
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.FlyStudio.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.TrojanX-gen.C5244877
Acronissuspicious
MAXmalware (ai score=80)
VBA32BScope.Backdoor.Poison
MalwarebytesMalware.AI.1320607851
TrendMicro-HouseCallTROJ_GEN.R002H0CIP22
RisingTrojan.Generic@AI.98 (RDML:YSvIrkZ/Uz0fYMhEOtwHhA)
IkarusTrojan-PWS.Win32.QQPass
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
BitDefenderThetaGen:NN.ZexaF.34698.@t0@a0aQC5nb
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.1320607851?

Malware.AI.1320607851 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment