Malware

Malware.AI.2064305745 information

Malware Removal

The Malware.AI.2064305745 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2064305745 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Attempts to masquerade or mimic a legitimate process or file name

How to determine Malware.AI.2064305745?


File Info:

name: F58B5E869178957B17D6.mlw
path: /opt/CAPEv2/storage/binaries/5443cd005b94d6f46fece25d05e791b51c3d6fe947a2cb9a2e2db8b5d082044d
crc32: 80E5AAC6
md5: f58b5e869178957b17d683172bdf45cc
sha1: e5fd83bf3c4294e8da7781a127162cd972bac1f4
sha256: 5443cd005b94d6f46fece25d05e791b51c3d6fe947a2cb9a2e2db8b5d082044d
sha512: d9870892e9f6c1476c054a1fffb371b361cd86437f457ed447fab47382c5ae05ecac7f013b7ef6a64355bfc0f5055e68b1cefcefe4a25eda98298e04b1313a4b
ssdeep: 6144:IYL7O613TM133QFsTppk13foWKnsM2v5RErPsNjs2BtQ7jr2maJp:IYe69A3QuTQ1voQM2RG7sjT+7vdaL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1777412846303CB69E6484A35602EE786CF13FF699E575AC436417B8FF9329D41E2E218
sha3_384: 9cd4e06d57e51947ed5b7fa4555fe0e8a70066c7eda045b87cd19a008dc2d32c39869682dc0c79c9c4657e1eb424619f
ep_bytes: 60be00e042008dbe0030fdffc7870c10
timestamp: 2007-02-01 09:58:37

Version Info:

Comments:
CompanyName: Avira GmbH
FileDescription: Antivirus Control Center
FileVersion: 8.00.70.08
InternalName: Control Center
LegalCopyright: Copyright © 2008 Avira GmbH. All rights reserved.
LegalTrademarks: AntiVir® is a registered trademark of Avira GmbH, Germany.
OriginalFilename: avcenter.exe
PrivateBuild:
ProductName: AntiVir Workstation
ProductVersion: 8.00.70.08
SpecialBuild:
Translation: 0x0800 0x04b0

Malware.AI.2064305745 also known as:

LionicVirus.Win32.Lamer.ljKD
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.2739
MicroWorld-eScanGen:Heur.VIZ.!e!.1
FireEyeGeneric.mg.f58b5e869178957b
ALYacGen:Heur.VIZ.!e!.1
CylanceUnsafe
VIPREVirTool.Win32.Obfuscator.da!j (v)
SangforTrojan.Win32.Zbot.TQ
K7AntiVirusTrojan ( 004af95c1 )
AlibabaTrojanSpy:Win32/SpyEyes.7b64422b
K7GWTrojan ( 004af95c1 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.34232.umKfae2KjSmc
VirITTrojan.Win32.Winlock.EBJ
CyrenW32/S-5f8a72a3!Eldorado
SymantecTrojan.Spyeye
ESET-NOD32a variant of Win32/Kryptik.BHOZ
TrendMicro-HouseCallTROJ_SPYEYE.SMEP-R12
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.SpyEyes.dxe
BitDefenderGen:Heur.VIZ.!e!.1
NANO-AntivirusTrojan.Win32.SpyEyes.dcmup
SUPERAntiSpywareTrojan.Agent/Gen-Morix
AvastWin32:Trojan-gen
TencentWin32.Trojan-spy.Spyeyes.Eddr
Ad-AwareGen:Heur.VIZ.!e!.1
SophosMal/Generic-R + Mal/Zbot-AV
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
ZillyaTrojan.FakeAV.Win32.51218
TrendMicroTROJ_SPYEYE.SMEP-R12
McAfee-GW-EditionBehavesLike.Win32.MultiDropper.fc
EmsisoftGen:Heur.VIZ.!e!.1 (B)
IkarusTrojan.Win32.Spyeye
GDataGen:Heur.VIZ.!e!.1
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1919919
GridinsoftRansom.Win32.Zbot.sa
ViRobotTrojan.Win32.A.SpyEyes.339456[UPX]
MicrosoftPWS:Win32/Zbot.TQ
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R2551
McAfeeArtemis!F58B5E869178
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.AI.2064305745
APEXMalicious
RisingRansom.LockScreen!8.83D (CLOUD)
YandexTrojanSpy.SpyEyes!xDPw9KCg52I
SentinelOneStatic AI – Malicious PE
AVGWin32:Trojan-gen
Cybereasonmalicious.691789
PandaGeneric Malware

How to remove Malware.AI.2064305745?

Malware.AI.2064305745 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment