Malware

Malware.AI.1960409853 information

Malware Removal

The Malware.AI.1960409853 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1960409853 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Malware.AI.1960409853?


File Info:

name: CCE989E29A0415FC8916.mlw
path: /opt/CAPEv2/storage/binaries/386d591e1afaa0b859a6a264f70e44f7430afccff3b0b0955f82060f52f6aaf6
crc32: C8E2B740
md5: cce989e29a0415fc891610847edc8bd8
sha1: 5a6c161e08c841e110d74b07fa77a2919383aea4
sha256: 386d591e1afaa0b859a6a264f70e44f7430afccff3b0b0955f82060f52f6aaf6
sha512: 1163cbb4d6ebd073ea233033e2c7bd693a624469beacef544569138480c9e4952173ba421c9760a00c30ce2b75d69ada35de1250010df60e8d0888ee2e45825c
ssdeep: 1536:khrkTzNQydlv/ikWuo1exDSIPEYOTnXSe08hhPHwtWop6ea5mMhm3GdGab:k5UDndDSIMYOTX90+5HwYRf5mY0GYU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T140248F2BB081E4F6DC8309F11E9276E3E274BA321A384215FF96161EF6795F1D12742E
sha3_384: f09e05c75babc5d5e098191cc60bdad8fb992ecb5e6765d5aefff18ad31359fe1d7ff5f6d4546d893fd24c3beaa2b8b8
ep_bytes: b99cb04000b800800000e8b72a0000e8
timestamp: 2004-02-15 21:27:58

Version Info:

0: [No Data]

Malware.AI.1960409853 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Win32.Sality.H
FireEyeGeneric.mg.cce989e29a0415fc
McAfeeW32/Sality.i.gen
CylanceUnsafe
ZillyaBackdoor.PePatch.Win32.16205
SangforSuspicious.Win32.Save.a
K7AntiVirusVirus ( 0040f8141 )
K7GWVirus ( 0040f8141 )
Cybereasonmalicious.29a041
BaiduWin32.Trojan.Sality.m
CyrenW32/Sality.OCXO-0174
SymantecW32.Sality
ESET-NOD32Win32/Sality.X
APEXMalicious
KasperskyVirus.Win32.Sality.x
BitDefenderDropped:Win32.Sality.H
NANO-AntivirusVirus.Win32.Sality.ryed
AvastWin32:Sality-AV
TencentVirus.Win32.KuKu.tt
Ad-AwareDropped:Win32.Sality.H
SophosML/PE-A
ComodoWin32.Sality.X@d1pc
DrWebWin32.HLLP.Sector.28318
TrendMicroTROJ_SPNR.0BJC11
McAfee-GW-EditionBehavesLike.Win32.Adware.dz
EmsisoftDropped:Win32.Sality.H (B)
SentinelOneStatic AI – Malicious PE
AviraW32/Sality.g
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataDropped:Win32.Sality.H
CynetMalicious (score: 100)
Acronissuspicious
VBA32Virus.Sality.16109
ALYacDropped:Win32.Sality.H
MAXmalware (ai score=88)
MalwarebytesMalware.AI.1960409853
TrendMicro-HouseCallTROJ_SPNR.0BJC11
RisingBackdoor.KUKU!1.A155 (RDMK:cmRtazoi4gzeCyZUEc9Ijt5bKyua)
YandexTrojan.GenAsa!trUTzOkYLyE
IkarusVirus.Win32.Sality
MaxSecureVirus.W32.Sality.X
FortinetW32/Sality.I!tr
BitDefenderThetaGen:NN.ZexaF.34182.nmW@a0INKBbc
AVGWin32:Sality-AV
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Malware.AI.1960409853?

Malware.AI.1960409853 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment