Malware

Malware.AI.1996732640 information

Malware Removal

The Malware.AI.1996732640 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1996732640 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Malware.AI.1996732640?


File Info:

crc32: 3C913F71
md5: ec00a840b4762a3296c8866684020c57
name: EC00A840B4762A3296C8866684020C57.mlw
sha1: 5ff7c322caeb4387224c5b3937dec6be0d7ff416
sha256: cd5202b37111a79ebfddcc074be2d706972bc335b6be09440be66641a6354c18
sha512: 397d0954b81a6a51484399f663f13835f9b9f6f7b67ee0362dcac67f61a28efae45c7647e3827f9c1ea7a039e4a545e277fa0575a9fc9fe47b48a0bd4d3b9d67
ssdeep: 12288:rx2ZKccOffPdRVdByTiM6gNigNDZg0bq8Ca1B:r7ccOffPdRVd0tNigJ+8C2B
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Assembly Version: 6.4.4.9
LegalCopyright: Copyright xa9Palantir Technologies.
InternalName: Filmstrip
FileVersion: 6.4.4.9
CompanyName: Palantir Technologies
FileDescription: Programmers Divide Injecting Cloud
LegalTrademarks: Copyright xa9Palantir Technologies.
Comments: Programmers Divide Injecting Cloud
ProductName: Filmstrip
Languages: English
ProductVersion: 6.4.4.9
PrivateBuild: 6.4.4.9
OriginalFilename: Filmstrip.exe
Translation: 0x0409 0x04b0

Malware.AI.1996732640 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f700b1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26375
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.207833
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Filecoder.2ef76f3e
K7GWTrojan ( 004f700b1 )
Cybereasonmalicious.0b4762
SymantecDownloader
ESET-NOD32Win32/Filecoder.FS
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Spy.Win32.Zbot.zkyq
BitDefenderGen:Variant.Symmi.80974
NANO-AntivirusTrojan.Win32.Zbot.flnnyv
MicroWorld-eScanGen:Variant.Symmi.80974
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Symmi.80974
SophosML/PE-A + Troj/Ransom-FDS
ComodoMalware@#1ail355t0dv1h
BitDefenderThetaGen:NN.ZexaF.34770.Dq0@aSRhtlbi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_HPGen-37b
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.ec00a840b4762a32
EmsisoftGen:Variant.Symmi.80974 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanSpy.Zbot.fnry
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1128665
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.29FE76E
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Pulobe.A
ArcabitTrojan.Symmi.D13C4E
AegisLabTrojan.Win32.Zbot.4!c
GDataGen:Variant.Symmi.80974
Acronissuspicious
McAfeeArtemis!EC00A840B476
VBA32BScope.TrojanSpy.Zbot
MalwarebytesMalware.AI.1996732640
PandaTrj/CI.A
TrendMicro-HouseCallMal_HPGen-37b
RisingTrojan.Generic@ML.89 (RDML:7QH0IlP0tXFvCsN1nfenAw)
YandexTrojan.Igent.bSUHHL.2
IkarusTrojan-Ransom.Crysis
FortinetW32/Pulobe.A!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.1996732640?

Malware.AI.1996732640 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment