Malware

About “Malware.AI.1352717965” infection

Malware Removal

The Malware.AI.1352717965 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1352717965 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Malware.AI.1352717965?


File Info:

name: 1BDBD35BCC3F1E52D342.mlw
path: /opt/CAPEv2/storage/binaries/eef8f189b38e1e8dec936527744c5c3c37d99d6e8897cf76e2f3cd6dff2a80ff
crc32: C7011E9E
md5: 1bdbd35bcc3f1e52d34297d4fb132b9e
sha1: 5a5afe5775d09a4c25850ed54f803c64f13a95b4
sha256: eef8f189b38e1e8dec936527744c5c3c37d99d6e8897cf76e2f3cd6dff2a80ff
sha512: 2eb37dc21d878a5879fd0e015ebf0ee03c11632befb7e63537485ee0bb8c86b3e533e8eed210c77e5977a00d0a860dd8478079c7df4349b717b084f30f4d26f7
ssdeep: 12288:NNqDUiTuHH999vQOFM/xAD/kk0xkrOTPTPN:irY9j7FqeD/AmODJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11AB423D544C275B4E8AB243507A5F9E1529A486348DF2C898DC0C8CFA63FCC7FA96719
sha3_384: 484594077da3f57ba6c7009c5e90a78e6464544efe14ccaf712aafd320bc8d3d3619c5f172561d91678ddbf5707cf859
ep_bytes: 60be000044008dbe0010fcff5783cdff
timestamp: 2014-12-03 05:44:03

Version Info:

0: [No Data]

Malware.AI.1352717965 also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.Generic.1!c
FireEyeGeneric.mg.1bdbd35bcc3f1e52
McAfeeArtemis!1BDBD35BCC3F
CylanceUnsafe
K7AntiVirusUnwanted-Program ( 004ba7661 )
K7GWUnwanted-Program ( 004ba7661 )
Cybereasonmalicious.775d09
BitDefenderThetaGen:NN.ZexaE.34294.FmGfaGvFrdgi
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Keygen.KG potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002H06KQ21
Paloaltogeneric.ml
ClamAVWin.Malware.Agen-6997369-0
NANO-AntivirusTrojan.Win32.Keygen.ftzrrv
SophosKeygen (PUA)
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
EmsisoftApplication.Keygen (A)
IkarusPUA.Keygen.Piriform
GDataWin32.Trojan.Agent.YV6DEG
JiangminTrojan.GenericKD.ty
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.1352717965
APEXMalicious
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazozmTPd9igytjhd3+R3+1p5)
YandexPUP.Agent!4c8+ydEdzc4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/KeyGen

How to remove Malware.AI.1352717965?

Malware.AI.1352717965 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment