Malware

Malware.AI.1888485259 (file analysis)

Malware Removal

The Malware.AI.1888485259 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1888485259 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.1888485259?


File Info:

name: 4AF59F301544CFA9AA0E.mlw
path: /opt/CAPEv2/storage/binaries/a29fafbcafca4fa2233b603a40515481c86ab9b867e1d7f93e23b7c7f5e80b0d
crc32: 3CC2EE9E
md5: 4af59f301544cfa9aa0e39a331561669
sha1: e142f794539c5f8f3832dfb3069c8569c9c796be
sha256: a29fafbcafca4fa2233b603a40515481c86ab9b867e1d7f93e23b7c7f5e80b0d
sha512: e4a8c301f3cdf7fbcee9a9d236a2be5b69640eccdc69619579a8baf4ba320e3d5777011da961d7663b6f12d00e0df0a8a696a3f29ee3c8788563f329cd4daad7
ssdeep: 3072:dhWRLucUgixaU3fEekyq/Ubyeo2g+muZLSqzVoTesCrBIopzqtMJLGhRvKB:doRmxaU3Rkyq/4VgHuZOqWaLJzELY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DCC57D02B2D5A0BAD5AA123018762F365B7DBD064A21FA47A378FE5F5D313C1D82D31E
sha3_384: ab11a7fc167e5c0493bc5aa4178fc580211e7c9e8f088ae4bf77054c302e711cd272fa8efe7d40993fde2b17b21920b0
ep_bytes: 558bec6aff68f8186500688812640064
timestamp: 2006-02-01 23:02:14

Version Info:

Comments:
CompanyName: Sysinternals - www.sysinternals.com
FileDescription: Rootkit detection utility
FileVersion: 1.70
InternalName:
LegalCopyright: Copyright (C) 2005-2006 Bryce Cogswell and Mark Russinovich
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName: Sysinternals Rootkitrevealer
ProductVersion: 1.70
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.AI.1888485259 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Swisyn.4!c
Elasticmalicious (high confidence)
McAfeeArtemis!4AF59F301544
CylanceUnsafe
ZillyaTrojan.Swisyn.Win32.28359
CyrenW32/Swisyn.R.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Swisyn-6854761-0
NANO-AntivirusTrojan.Win32.TrjGen.czhguj
AvastWin32:Malware-gen
SophosML/PE-A
DrWebTrojan.Siggen4.42378
McAfee-GW-EditionBehavesLike.Win32.Dropper.vz
GDataWin32.Trojan.PSE.1NQVQOX
Antiy-AVLTrojan/Generic.ASMalwS.9DB64B
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Swisyn
MalwarebytesMalware.AI.1888485259
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazrXBOMTKtd5hcZHuGs6nKuT)
IkarusTrojan.Win32.Swisyn
FortinetW32/Swisyn.R!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.1888485259?

Malware.AI.1888485259 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment