Malware

Malware.AI.1353237304 removal

Malware Removal

The Malware.AI.1353237304 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1353237304 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the EnigmaStub malware family
  • Anomalous binary characteristics

How to determine Malware.AI.1353237304?


File Info:

name: 60B802938E04E1118A4B.mlw
path: /opt/CAPEv2/storage/binaries/643ca650061e5018297122c5d4365104b4dcb1be68674c76066cd8a1c1e82acf
crc32: A9AF02E3
md5: 60b802938e04e1118a4b5dc7b7ea1168
sha1: 8e8d73575b18ee970323d7191c7e83aaa6572bff
sha256: 643ca650061e5018297122c5d4365104b4dcb1be68674c76066cd8a1c1e82acf
sha512: 99255f0ee56d79208a9959c13c2dbbc1e7d0b6d884a0f6e05cbccc17ad6bba934c598d4d92b1c647ecb50cd2c7714a576145e514f00800f24af6b364b5ea49fe
ssdeep: 49152:fwab6tJdmUUkYcOuivjv+Yo7YVW3EOiCcv:p6tydcEvjvceWzO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10875234086F89669F5B5EB3CA9FD5B540D25BE95AD30F50901E04C0F78B7B218AE0B2A
sha3_384: 3e50f5aed8f6b6cf20d718e3ed62af3a002af103f77da3811b9efb93ed5f617028e2d19ae747d829b1389a3ba022993a
ep_bytes: eb08001c09000000000060e800000000
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Synaptics
FileDescription: Synaptics Pointing Device Driver
FileVersion: 1.0.0.4
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
Comments:
Translation: 0x041f 0x04e6

Malware.AI.1353237304 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.784850
FireEyeGeneric.mg.60b802938e04e111
ALYacGen:Variant.Ursu.784850
CylanceUnsafe
K7AntiVirusAdware ( 005693e61 )
K7GWAdware ( 005693e61 )
Cybereasonmalicious.38e04e
BitDefenderThetaGen:NN.ZexaF.34084.IT0@aq14sgiG
CyrenW32/Parasitic-Fileinfector-base
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.EnigmaProtector.M suspicious
ClamAVWin.Packed.Enigmaprotector-9634996-0
KasperskyUDS:Trojan-Downloader.Win32.Murlo
BitDefenderGen:Variant.Ursu.784850
Ad-AwareGen:Variant.Ursu.784850
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Ursu.784850 (B)
IkarusVirus.Win32.Delf
GDataGen:Variant.Ursu.784850
JiangminWin32/Synaptics.Gen
AviraDR/Delphi.Gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Antisb.R422694
Acronissuspicious
McAfeeArtemis!60B802938E04
VBA32Trojan.Wacatac
MalwarebytesMalware.AI.1353237304
APEXMalicious
YandexTrojan.GenAsa!A4m6kiNwPUg
MAXmalware (ai score=83)
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.1353237304?

Malware.AI.1353237304 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment