Malware

How to remove “Malware.AI.1322453168”?

Malware Removal

The Malware.AI.1322453168 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1322453168 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Hebrew
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings

How to determine Malware.AI.1322453168?


File Info:

name: E481E8766662630CD6E2.mlw
path: /opt/CAPEv2/storage/binaries/bf1dc98393787ca906d9c5b41717749f10ed58299f6d047ea6710f0ee8d4a376
crc32: 7AECAE23
md5: e481e8766662630cd6e20a72983e584d
sha1: 016beaf9791989dfded59cfad6385b44f822d327
sha256: bf1dc98393787ca906d9c5b41717749f10ed58299f6d047ea6710f0ee8d4a376
sha512: 939fef6d7297147bef4e90ee4c3ad13e1ed38817f29b4088259d3333fc0f2cf5fdfd77908a814909cde937dd8cc6c90022f9a6920bef4a65f3c251d558552cc9
ssdeep: 3072:bf/PHtXZAvr28XZgXZM7yodIXuqOrcja95LTKZ6SUbTOP5Iu:bfnlZAz7XZp7yFuqOumTKZ6N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18604A34371608B63DEDE2B39746AA93A993CFD42DF7046AD7140E9D6206BE07EC10397
sha3_384: ba9cd64f50fd0234239179d4c4f4fedb84cedab3edd7a847f04f14cc4a42411389d1091ed0023d25cc7ce10204d139d6
ep_bytes: 558bec83ec105357c745fc01000000c7
timestamp: 2014-07-04 13:01:29

Version Info:

CompanyName: NirSoft
FileDescription: WhatInStartup
FileVersion: 1.33
InternalName: WhatInStartup
LegalCopyright: Copyright © 2009 - 2011 Nir Sofer
OriginalFilename: WhatInStartup.exe
ProductName: WhatInStartup
ProductVersion: 1.33
Translation: 0x0409 0x04b0

Malware.AI.1322453168 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebBackDoor.Kuluoz.4
MicroWorld-eScanGen:Variant.Application.Locky.6
FireEyeGeneric.mg.e481e8766662630c
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacGen:Variant.Application.Locky.6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 0040f8df1 )
K7GWTrojan-Downloader ( 0040f8df1 )
Cybereasonmalicious.666626
BitDefenderThetaGen:NN.ZexaF.34182.lq0@aSMP4VeO
VirITTrojan.Win32.Crypt3.ACTC
CyrenW32/Agent.ABK.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.CFYJ
TrendMicro-HouseCallBKDR_KULUOZ.SM02
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Application.Locky.6
NANO-AntivirusTrojan.Win32.Dofoil.dbztxa
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b47de1
SophosML/PE-A + Troj/Kuluoz-AV
ComodoTrojWare.Win32.TrojanDownloader.Dofoil.AYY@5cjcwk
ZillyaDownloader.Dofoil.Win32.1067
TrendMicroBKDR_KULUOZ.SM02
McAfee-GW-EditionPacked-AM!E481E8766662
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Application.Locky.6 (B)
IkarusTrojan.Win32.Kryptik
JiangminTrojan.Generic.fgdqe
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1237750
MicrosoftTrojanDownloader:Win32/Kuluoz.D
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Application.Locky.6
CynetMalicious (score: 100)
AhnLab-V3HEUR/Malga.D708.X1491
McAfeePacked-AM!E481E8766662
TACHYONTrojan-Downloader/W32.Dofoil.185856.B
VBA32BScope.Trojan.Jorik
MalwarebytesMalware.AI.1322453168
APEXMalicious
RisingDownloader.Kuluoz!8.83A (RDMK:cmRtazqEg7w16eRbhC4clTPbIV3j)
YandexTrojan.DL.Dofoil!aWpzf+EPH0A
MAXmalware (ai score=74)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dridex.DD!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1322453168?

Malware.AI.1322453168 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment