Malware

How to remove “Malware.AI.1357696534”?

Malware Removal

The Malware.AI.1357696534 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1357696534 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Malware.AI.1357696534?


File Info:

name: BF97E09016E5E6A65968.mlw
path: /opt/CAPEv2/storage/binaries/8263e0db727be2660f66e2e692b671996c334400d83e94fc0355ec0949dce05c
crc32: 441D8B62
md5: bf97e09016e5e6a65968933f94d10a1d
sha1: e0bf3066f06fef0cc7aff20b6dc3655a40354e64
sha256: 8263e0db727be2660f66e2e692b671996c334400d83e94fc0355ec0949dce05c
sha512: 1fa36c734dbd2026dc8b23f5d682a50e200342dab3a727dbaccf91096ca50bb8e892551d9038176b8808d687fb03f01ef4e95a0dc9d6941e8673364860b03a38
ssdeep: 12288:9AEO+qWr7lSKi4BgRT1fPVWBoMXOFiQlBlKHRdoWOsJzZgVz:9DO+qWHg5rRpfPAo+O3vlKUW7JGVz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E1D4AD267BA0E172C26230F04A9AE77576B9AC705F3A47877BD01A3D1F345D15A3833A
sha3_384: a46043660fdd0fb3115bb9bcb95790c6b3e9f984a69d934790d1bc20b0104e71a1c0ed649368d22097f80eb956ce1076
ep_bytes: e86bc60000e978feffff8bff558bec6a
timestamp: 2018-08-15 11:42:27

Version Info:

Languages: English
Assembly Version: 7.6.2.8
PrivateBuild: 7.6.2.8
Comments: Underreported Businesses 360
CompanyName: Realsil Microelectronics Inc.
FileDescription: Underreported Businesses 360
LegalTrademarks: Realsil Microelectronics Inc. Copyright ©. All rights reserved.
OriginalFilename: ServicesPainter
FileVersion: 7.6.2.8
LegalCopyright: Realsil Microelectronics Inc. Copyright ©. All rights reserved.
InternalName: ServicesPainter
ProductName: ServicesPainter
ProductVersion: 7.6.2.8
Translation: 0x0409 0x04b0

Malware.AI.1357696534 also known as:

LionicTrojan.Win32.Zbot.l!c
MicroWorld-eScanGen:Variant.Jatif.1119
FireEyeGeneric.mg.bf97e09016e5e6a6
ALYacTrojan.Zbot.Gen
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.157921
SangforTrojan.Win32.Zbot.zegx
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Kryptik.c4362f04
K7GWTrojan ( 0053458c1 )
K7AntiVirusTrojan ( 0053458c1 )
CyrenW32/Trojan.VYRR-8416
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GKHL
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.CobInt-6699267-0
KasperskyTrojan-Spy.Win32.Zbot.zegx
BitDefenderGen:Variant.Jatif.1119
NANO-AntivirusTrojan.Win32.Zbot.fhrmjh
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.114d30ee
Ad-AwareGen:Variant.Jatif.1119
EmsisoftGen:Variant.Jatif.1119 (B)
ComodoMalware@#2qgmrjleww7kq
DrWebTrojan.DownLoader26.62702
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PJ121
McAfee-GW-EditionTrojan-Zbot
SophosMal/Generic-S
GDataGen:Variant.Jatif.1119
JiangminTrojanSpy.Zbot.fneq
WebrootW32.Trojan.Gen
AviraTR/Kryptik.gygen
Antiy-AVLTrojan/Generic.ASMalwS.27BDAE8
ViRobotTrojan.Win32.Z.Zbot.639696
MicrosoftPUAAdvertising:Win32/LoadMoney
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C3112321
McAfeeTrojan-Zbot
MAXmalware (ai score=100)
VBA32BScope.Trojan.Banker
MalwarebytesMalware.AI.1357696534
TrendMicro-HouseCallTROJ_GEN.R002C0PJ121
RisingSpyware.Zbot!8.16B (CLOUD)
IkarusTrojan-Spy.Remcos
MaxSecureTrojan.Malware.11902872.susgen
FortinetW32/GenKryptik.CIIC!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.016e5e
PandaTrj/CI.A

How to remove Malware.AI.1357696534?

Malware.AI.1357696534 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment