Malware

How to remove “Malware.AI.1960746858”?

Malware Removal

The Malware.AI.1960746858 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1960746858 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

Related domains:

anas12.zapto.org

How to determine Malware.AI.1960746858?


File Info:

crc32: FC1C497D
md5: caa5bf26af6854fb5f61f95e16a83250
name: CAA5BF26AF6854FB5F61F95E16A83250.mlw
sha1: 5ea82d73e576e68f3c701137089fa756b06eab57
sha256: 5b661072ef23411a2414e96071a53a310a971eef710448ee07686fb8b050bfd3
sha512: d64ff87c30228003f65ad2c543df40868460e4723fc447115b2cd0002b70fa0c67b0a7e2709557ba9b81f25d4a43b85c35b60a7f9d44db7f3dcba06f7c014b49
ssdeep: 6144:cnCDazRzAtyAKKZum1em//2N0rWyP6kNP41hYy+22aZTZq2+Pf:cnAa5ugmxuN0r+cP+Yy+22aZFq2+
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2012
Assembly Version: 1.0.0.0
InternalName: king.exe
FileVersion: 1.0.0.0
ProductName: WindowsApplication2
ProductVersion: 1.0.0.0
FileDescription: WindowsApplication2
OriginalFilename: king.exe

Malware.AI.1960746858 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Krypt.2
FireEyeGeneric.mg.caa5bf26af6854fb
ALYacGen:Heur.MSIL.Krypt.2
CylanceUnsafe
VIPRETrojan.MSIL.Rebhip.s (v)
AegisLabTrojan.Win32.Generic.lI3I
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Heur.MSIL.Krypt.2
K7GWTrojan ( 700000121 )
Cybereasonmalicious.6af685
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/DotNetInject.F!generic
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/Injector.650a0d72
NANO-AntivirusTrojan.Win32.Autoruner.dclris
AvastWin32:Dropper-LNB [Drp]
TencentWin32.Trojan.Generic.Tayn
Ad-AwareGen:Heur.MSIL.Krypt.2
EmsisoftGen:Heur.MSIL.Krypt.2 (B)
ComodoTrojWare.MSIL.Injector.AEK@5iegdc
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner.25074
ZillyaTrojan.Injector.Win32.294077
McAfee-GW-EditionGenericRXEI-EV!CAA5BF26AF68
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.ukye
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Unknown
MicrosoftWorm:Win32/Rebhip
ArcabitTrojan.MSIL.Krypt.2
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.MSIL.Krypt.2
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.R326386
Acronissuspicious
McAfeeGenericRXEI-EV!CAA5BF26AF68
MAXmalware (ai score=100)
MalwarebytesMalware.AI.1960746858
ESET-NOD32a variant of MSIL/Injector.CJV
RisingWorm.Rebhip!8.B31 (CLOUD)
IkarusTrojan.MSIL.Injector
FortinetMSIL/Injector.VA!tr
BitDefenderThetaAI:Packer.C974AACD1F
AVGWin32:Dropper-LNB [Drp]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/TrojanDropper.Generic.HwMASzAA

How to remove Malware.AI.1960746858?

Malware.AI.1960746858 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment