Malware

Malware.AI.1672439359 removal guide

Malware Removal

The Malware.AI.1672439359 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1672439359 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.1672439359?


File Info:

name: B81E936CDAEC36BFD342.mlw
path: /opt/CAPEv2/storage/binaries/a2efacec5f7505e4631bec7cf55464419e051b4347e44ac85ca834492a2e4f55
crc32: F3C9F65E
md5: b81e936cdaec36bfd342765c58033a74
sha1: 955eefab87b296ca2d6fda669436e906e5ae231a
sha256: a2efacec5f7505e4631bec7cf55464419e051b4347e44ac85ca834492a2e4f55
sha512: ffe14500c8ac1ef7d6dbf69bbcbeb0a2ae6a26d73e6523065944ebc67637b8d02340709893f54a04d7942e43b75e54904264e25c8bc5b3be72ae526a8584d14b
ssdeep: 98304:m2/tUO5DVtkNjFWnAC6iZHSqTIueYqwEwBYoHC1K3c17fG+QP5:5CO5RtkNhhrCSqutwBdH4V1aZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C3633E3996B4CC5C1613B3A912F7E4121D35836EE8A0DF74338D48A7D36D8ED1A9382
sha3_384: e77def16c80c7b02e42b51d17bbffeab58d25815d66380c24b165fbbc4bfb4ce66c5f4cde0243924b39fcf866cafddd9
ep_bytes: 60be00c06d008dbe0050d2ff57eb0b90
timestamp: 2019-02-03 13:56:58

Version Info:

Translation: 0x0809 0x04b0

Malware.AI.1672439359 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Diple.4!c
DrWebTrojan.MulDrop9.2830
MicroWorld-eScanAIT:Trojan.Nymeria.1679
FireEyeGeneric.mg.b81e936cdaec36bf
CAT-QuickHealTrojan.AutoIt.Wacatac.E
McAfeeArtemis!B81E936CDAEC
CylanceUnsafe
ZillyaDropper.Diple.Win32.1
K7AntiVirusTrojan ( 005472431 )
AlibabaTrojan:Win32/Diple.d326b69d
K7GWTrojan ( 005472431 )
Cybereasonmalicious.cdaec3
BitDefenderThetaAI:Packer.05A1835A17
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.JMWZXNB
Paloaltogeneric.ml
ClamAVWin.Trojan.Autoit-7351498-0
KasperskyTrojan.Win32.Diple.hifk
BitDefenderAIT:Trojan.Nymeria.1679
TencentWin32.Trojan.Diple.Pdvy
Ad-AwareAIT:Trojan.Nymeria.1679
EmsisoftAIT:Trojan.Nymeria.1679 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.rc
SophosMal/Generic-S + Mal/AuItInj-A
IkarusTrojan.Win32.Injector
GDataAIT:Trojan.Nymeria.1679 (3x)
AviraDR/AutoIt.Gen8
MAXmalware (ai score=100)
ArcabitAIT:Trojan.Nymeria.D68F
MicrosoftTrojan:Win32/Occamy.CA2
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C3001720
VBA32Trojan.Diple
ALYacAIT:Trojan.Nymeria.1679
MalwarebytesMalware.AI.1672439359
APEXMalicious
RisingTrojan.Diple!8.46B (CLOUD)
YandexTrojan.Diple!AE+hRE5yUAs
FortinetAutoIt/Agent.DRJ!tr
PandaTrj/CI.A

How to remove Malware.AI.1672439359?

Malware.AI.1672439359 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment