Malware

Malware.AI.1328295631 removal guide

Malware Removal

The Malware.AI.1328295631 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1328295631 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Arabic (Algeria)
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.1328295631?


File Info:

name: D9CFA2EBD8C0818B9FFA.mlw
path: /opt/CAPEv2/storage/binaries/cf635fe6eb7cb044df91ec142d6c1eb3979cd4a9fe0d2b739cd774ca57deea2a
crc32: D3609DA3
md5: d9cfa2ebd8c0818b9ffa2bef77d98045
sha1: 58eeb16f757df78f607c24f582f153e08eaf3465
sha256: cf635fe6eb7cb044df91ec142d6c1eb3979cd4a9fe0d2b739cd774ca57deea2a
sha512: 13d83f0a9b7697d6d85725985f0ba157d8603b8032c402f2397a58d42ceffc392fbae8f18b6213d35bd97648d9da209f46281122f43fd51dc3c6e202d7db25ad
ssdeep: 12288:OVRB+k677/T7ovvYu+3pWUN1gZakagGWrNO1HjiTq7zqkH8s1fqUx:OVRB27MHYuUDRjgGb1HtqkBfqy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17E55F012B7F8456CF1F36B345875A75189B8BC33DA318B6D0AC016AD1E34991AE20FB7
sha3_384: 243de6db1f0c522766af9888458d3b5e709fb9ea35f142494a68366a89d81a646aa5921142f53001a6a0d749471cc7a3
ep_bytes: e826050000e98efeffff558bec6a00ff
timestamp: 2018-05-08 22:44:45

Version Info:

CompanyName: Google Inc.
FileDescription: Google Installer
FileVersion: 1.3.33.17
InternalName: Google Update
LegalCopyright: Ауторска права 2007–2010. Google Inc.
OriginalFilename: GoogleUpdate.exe
ProductName: Google ажурирање
ProductVersion: 1.3.33.17
Translation: 0x081a 0x04e2

Malware.AI.1328295631 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Waldek.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.d9cfa2ebd8c0818b
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0058c5701 )
K7AntiVirusTrojan ( 0058c5701 )
CyrenW32/Expiro.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.NDP
APEXMalicious
ClamAVWin.Trojan.Expiro-9933702-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:FileInfector-C [Heur]
TencentWin32.Virus.Expiro.Wuhj
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.tt
IkarusTrojan.Patched
eGambitUnsafe.AI_Score_99%
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.FileInfector.R461844
Acronissuspicious
VBA32Trojan.Sabsik.TE
MalwarebytesMalware.AI.1328295631
TrendMicro-HouseCallTROJ_GEN.R002H0CA422
RisingVirus.Expiro!8.375 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Expiro.NDO!tr
AVGWin32:FileInfector-C [Heur]
Cybereasonmalicious.f757df

How to remove Malware.AI.1328295631?

Malware.AI.1328295631 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment