Malware

What is “Malware.AI.1352297906”?

Malware Removal

The Malware.AI.1352297906 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1352297906 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Creates RWX memory
  • Unconventionial binary language: Arabic (Algeria)
  • Unconventionial language used in binary resources: Serbian (Cyrillic)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.1352297906?


File Info:

name: 69BA8A30CEDB8091566C.mlw
path: /opt/CAPEv2/storage/binaries/a97c04365d6dba5afd4eb77319f0da7ebb7638036f1a20df37ba3eb481b30c21
crc32: 30B9DF25
md5: 69ba8a30cedb8091566c192c01c1b3c2
sha1: c51b733bbc4ce54a7fe17dc8f91ba12a7358a474
sha256: a97c04365d6dba5afd4eb77319f0da7ebb7638036f1a20df37ba3eb481b30c21
sha512: 323c3fd3022a29c08ae66a16b031ae0ee825f207aaa78523fdbd15a9f96a01b6f6c83246bce565d1bdbea3b50413fec7100640fe8152296d7298ccac07bfbde2
ssdeep: 12288:oERB+k6Ft7mMn4bi4uNXeRJ7TtY/aJwvgC7EOp:oERB2FtiqHZyJ7G/a2uO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FC47D43B2E801E8E9B627311976FF4491F97A62DE24DBCC1DC438F93C77A806514AB6
sha3_384: 5afa98969c6bf66269e3367f87bf410adc37bd5fbe8e655d0a7fcfa051497f37d5841e00299acec8791a3dac8e1e7ede
ep_bytes: 5150528d0d18000000648b0101c801c8
timestamp: 2018-01-10 23:09:47

Version Info:

CompanyName: Google Inc.
FileDescription: Google Installer
FileVersion: 1.3.33.17
InternalName: Google Update
LegalCopyright: Ауторска права 2007–2010. Google Inc.
OriginalFilename: GoogleUpdate.exe
ProductName: Google ажурирање
ProductVersion: 1.3.33.17
Translation: 0x081a 0x04e2

Malware.AI.1352297906 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Expiro.Gen.6
FireEyeGeneric.mg.69ba8a30cedb8091
ALYacWin32.Expiro.Gen.6
CylanceUnsafe
VIPREVirus.Win32.Expiro.dp (v)
SangforTrojan.Win32.Save.a
Cybereasonmalicious.0cedb8
VirITWin32.Expiro.CV
CyrenW32/S-e2b0e511!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Expiro.NDG
APEXMalicious
KasperskyHEUR:Trojan.Win32.Expiro.gen
BitDefenderWin32.Expiro.Gen.6
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Xpirat-C [Inf]
Ad-AwareWin32.Expiro.Gen.6
EmsisoftWin32.Expiro.Gen.6 (B)
DrWebWin32.Expiro.150
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosML/PE-A
IkarusVirus.Win32.Expiro
GDataWin32.Expiro.Gen.6
JiangminTrojan.PSW.Stealer.abj
AviraW32/Infector.Gen8
Antiy-AVLTrojan/Generic.ASVirus.315
MicrosoftTrojan:Win32/Raccoon.EC!MTB
CynetMalicious (score: 100)
Acronissuspicious
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.1352297906
RisingMalware.Heuristic!ET#89% (RDMK:cmRtazqkKJb4wIS/XV/gniEoqipw)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Expiro.NDG
BitDefenderThetaGen:NN.ZexaF.34114.Hy0@aC!zrfgP
AVGWin32:Xpirat-C [Inf]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1352297906?

Malware.AI.1352297906 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment