Malware

Malware.AI.1376727925 information

Malware Removal

The Malware.AI.1376727925 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1376727925 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location

How to determine Malware.AI.1376727925?


File Info:

name: 87850C149E2129087799.mlw
path: /opt/CAPEv2/storage/binaries/d73eb5fbe21cf21c412dfad3bd543e5b06042740f2d4ad07e9ad12f198625100
crc32: 73E29AC8
md5: 87850c149e21290877991ab842b6d65c
sha1: 04f22396bde11f56f4d732a656c64651a733f6a1
sha256: d73eb5fbe21cf21c412dfad3bd543e5b06042740f2d4ad07e9ad12f198625100
sha512: 539f63cccfbd39622b29acc60e186a5c1c6054aa2d9a226e41c7d5338e7263e24029b75988367446918018485c9874e8376d9210dc1fe29f9d908759edaa43c0
ssdeep: 1536:J9wx4brpfa7IxGYv8uSyjZrVilyyNXUNN833vkvLv58x144:Twxgpfeuv/RyDoN83fkv7Y44
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E283D0913487F5DDC24BD976876E0F84C37F283B208123FB4E691899AF55D1221CEDA9
sha3_384: 4454357a60ea4aabf28ae8cc83f59ab07fb35bf9c4a3708bae57239cd75f63b70b7558453441343aae0f412dee87138d
ep_bytes: b935c7cc3429ff21d368188640006800
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Malware.AI.1376727925 also known as:

MicroWorld-eScanGen:Variant.Razy.373481
ALYacGen:Variant.Razy.373481
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058e60a1 )
K7GWTrojan ( 0058e60a1 )
Cybereasonmalicious.49e212
CyrenW32/Zbot.W.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Razy.373481
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Susp]
TencentTrojan.Win32.Copak.zd
Ad-AwareGen:Variant.Razy.373481
EmsisoftGen:Variant.Razy.373481 (B)
DrWebTrojan.Siggen18.9828
McAfee-GW-EditionBehavesLike.Win32.Glupteba.mc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.87850c149e212908
SophosML/PE-A + Mal/EncPk-ADN
IkarusTrojan.Win32.Injector
GDataGen:Variant.Razy.373481
AviraTR/Crypt.XPACK.Gen
ArcabitTrojan.Razy.D5B2E9
MicrosoftTrojan:Win32/Zusy.DKL!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R419438
Acronissuspicious
McAfeeGenericRXTI-BC!9C1304C9682C
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.1376727925
RisingTrojan.Kryptik!1.D284 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.T!tr
BitDefenderThetaGen:NN.ZexaF.34742.fuW@aiaVaNg
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.1376727925?

Malware.AI.1376727925 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment