Malware

About “Malware.AI.1372122236” infection

Malware Removal

The Malware.AI.1372122236 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1372122236 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Binary compilation timestomping detected

How to determine Malware.AI.1372122236?


File Info:

name: DD9478C68A6266FE0DE8.mlw
path: /opt/CAPEv2/storage/binaries/58744eb838f705217fef2e84ae16fc3105dece3ee99dd28089d7251456b397cc
crc32: 99658201
md5: dd9478c68a6266fe0de85924380a7ee8
sha1: 455bddd3b811be6c79a52c868bd2d79815c8745e
sha256: 58744eb838f705217fef2e84ae16fc3105dece3ee99dd28089d7251456b397cc
sha512: df1e8bc1453e9cd26b5e65e23a1de728b46ea48dded6756061eac8a3140c9a002dad2f81e11652c84428284e2d5bfe3c374962e18084c902cdb2d7085d4991ec
ssdeep: 24576:2djAXKChvKoQUivtDgpAJpMoJDV6TUyeJev5oBjXxgLz2m8E2xAWz8bqM36xtIY:4kSojivtcCMoJh6TUfGgKqAhbv3SI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173651317F3A3A304C9EC45725D81CD582BA2F50E5C178933B2BAC7867AB23437D267A5
sha3_384: 2c5d92c6050e890c94f02c75eb184ac7eef8fd04ecd6477c931953442e3f9765f80375126a5aefe5007cb55eb1c7cb3a
ep_bytes: ff250020400000000000000000000000
timestamp: 2064-05-22 01:04:27

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: csrss
FileVersion: 1.0.0.0
InternalName: csrss.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: csrss.exe
ProductName: csrss
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.1372122236 also known as:

LionicTrojan.MSIL.Diztakun.4!c
DrWebTrojan.Siggen13.27486
MicroWorld-eScanTrojan.GenericKD.36882792
FireEyeTrojan.GenericKD.36882792
ALYacTrojan.GenericKD.36882792
CylanceUnsafe
SangforTrojan.MSIL.Diztakun.gen
K7AntiVirusTrojan ( 005082b31 )
AlibabaTrojan:MSIL/Diztakun.8e6a5596
K7GWTrojan ( 005082b31 )
BitDefenderThetaGen:NN.ZemsilF.34084.Bn0@aqf07Fn
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.MPLVQWQ
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Diztakun.gen
BitDefenderTrojan.GenericKD.36882792
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Wuqu
Ad-AwareTrojan.GenericKD.36882792
EmsisoftTrojan.GenericKD.36882792 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WL121
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.zgem
MaxSecureTrojan.Malware.73704538.susgen
AviraTR/Diztakun.asbdw
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataTrojan.GenericKD.36882792
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4470166
McAfeeArtemis!DD9478C68A62
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.1372122236
TrendMicro-HouseCallTROJ_GEN.R002C0WL121
IkarusTrojan.SuspectCRC
eGambitUnsafe.AI_Score_99%
FortinetPossibleThreat
AVGWin32:Malware-gen
PandaTrj/GdSda.A

How to remove Malware.AI.1372122236?

Malware.AI.1372122236 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment