Malware

Malware.AI.1588329570 removal guide

Malware Removal

The Malware.AI.1588329570 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1588329570 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • A script or command line contains a long continuous string indicative of obfuscation
  • Uses suspicious command line tools or Windows utilities

Related domains:

wpad.local-net
www.safeactivation.com

How to determine Malware.AI.1588329570?


File Info:

name: 146726CA569B864EB22D.mlw
path: /opt/CAPEv2/storage/binaries/532c79f41c9ceaf5b1513af7ba27e2807148678ee71d6cd30bc5ba968172c42d
crc32: 66F84937
md5: 146726ca569b864eb22d8ac43a2ff488
sha1: e9aa724b0efae1f9a1f10e708ef43e63df74c870
sha256: 532c79f41c9ceaf5b1513af7ba27e2807148678ee71d6cd30bc5ba968172c42d
sha512: be11bc52684843341a513e389d82f1ff89477cd4a486ed59946f5e7ffe0526efb0a02a62f07f9bc3cc1c472aab3945f5a33c787a9e8be5d7f52b4d5b79838414
ssdeep: 49152:kRdvYcFIpkYiSOXQJXJesCWo+XkT/Htrm8zhY4Vf9cidvZ1AkEljls9NzWbkzpe8:EdgrJeqo4AV67Wf9cidh1Ak1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BD167D12B28A503BD0772B3A4C77D694583FBD242A35885B3AAC1D1D0F36A42B93F757
sha3_384: 5f07616bbc648894504753e076bb5bfd0b9226ad1d93a53481ea2ddb072043b265e717695fc31617a3888ba181116461
ep_bytes: 558bec83c4f0b83c0a6600e884e6d9ff
timestamp: 2014-07-11 17:51:21

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Malware.AI.1588329570 also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.KillProc.48459
FireEyeGeneric.mg.146726ca569b864e
McAfeeArtemis!146726CA569B
CylanceUnsafe
SangforTrojan.Win32.Malware.gen
BitDefenderThetaAI:Packer.DC0E356819
ClamAVWin.Malware.Killproc-5403059-0
NANO-AntivirusTrojan.Win32.KillProc.eiwrlj
AvastWin32:Malware-gen
ComodoMalware@#1orqvm9mvkj83
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
SentinelOneStatic AI – Malicious PE
IkarusTrojan.Agent
MaxSecureTrojan.Malware.300983.susgen
MicrosoftTrojan:Win32/Occamy.C53
CynetMalicious (score: 100)
VBA32BScope.Trojan.KillProc
MalwarebytesMalware.AI.1588329570
APEXMalicious
YandexTrojan.GenAsa!Ky0IenfiH9s
MAXmalware (ai score=99)
WebrootW32.Trojan.GenKD
AVGWin32:Malware-gen
Cybereasonmalicious.a569b8
PandaTrj/CI.A

How to remove Malware.AI.1588329570?

Malware.AI.1588329570 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment