Malware

About “Malware.AI.1965678874” infection

Malware Removal

The Malware.AI.1965678874 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1965678874 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • NtSetInformationThread: attempt to hide thread from debugger
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library

How to determine Malware.AI.1965678874?


File Info:

name: D7AF62F631EB9794C8C2.mlw
path: /opt/CAPEv2/storage/binaries/b9968d12a6772b2ef07313fbd86c2c571a23d952ead7c596acfc4c26c30faf92
crc32: A074D175
md5: d7af62f631eb9794c8c206e5c9955eae
sha1: b6687232453405b16f20c32c436a75bd3078d724
sha256: b9968d12a6772b2ef07313fbd86c2c571a23d952ead7c596acfc4c26c30faf92
sha512: 3a75a6dc3862f4855ecb5381a386fd3e8d8466ed7223d970d4d9c7bde4a212fe37fb23c97b7e864adc6db711a4ca9f666dad0658cb6adb6ddb6f199b11afc596
ssdeep: 98304:SINe36FoWokCe/UthjTcZLXgnaESAyHLBFLOAkGkzdnEVomFHKnP+Q:SJ36Fo2ESAyHLBFLOyomFHKnPj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14326CF613F4A3066D8F34131CA99F7BCA16EBE7C973900EB5190B62D79316814A3973B
sha3_384: da11d37fc71f660aeb8d06d85ec5962da6c252c6d6284d72442f68321700c969db40bce45380c61f33cc91a813188867
ep_bytes: e8b8550000f86854dceec29ce89f4a00
timestamp: 2022-04-27 06:49:15

Version Info:

CompanyName: TODO:
FileDescription: MFCApplication2
FileVersion: 1.0.1.0
InternalName: MFCApplication2
LegalCopyright: TODO: (C) 。 保留所有权利。
OriginalFilename: MFCApplication2
ProductName: TODO:
ProductVersion: 1.0.1.0
Translation: 0x0804 0x04b0

Malware.AI.1965678874 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CylanceUnsafe
K7AntiVirusTrojan ( 7000001c1 )
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.245340
SymantecPacked.Vmpbad!gen9
ESET-NOD32a variant of Win32/Packed.VMProtect.AAM
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
SophosMal/VMProtBad-A
ComodoVirus.Win32.Virut.CE@1fhkga
FireEyeGeneric.mg.d7af62f631eb9794
AviraTR/Black.Gen2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32suspected of Trojan.Downloader.gen
MalwarebytesMalware.AI.1965678874
BitDefenderThetaGen:NN.ZexaF.34638.@F1@aumpDNab
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.1965678874?

Malware.AI.1965678874 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment