Malware

Malware.AI.2131725873 malicious file

Malware Removal

The Malware.AI.2131725873 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2131725873 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Malware.AI.2131725873?


File Info:

crc32: D089EB52
md5: 133287a979f678ab01b1891c5a9ff90b
name: 133287A979F678AB01B1891C5A9FF90B.mlw
sha1: aa4b14ade58222ee284a10fe4d46e5c0d3f11df1
sha256: c84fb8eb1aec81b35db8bd547aad36febe7f6af9f7422e166d5a044bc9a278e9
sha512: d6d536e15b2acceada50afdbc4bcab1c9e1ed587a1f93298f9d08d0cae06f532c8680cfef2c14975bfc9c29f2627d580e23e219a89a13123d7847772bea20716
ssdeep: 12288:3LmAAkA7scFfc0oU+hrrl7Xvs0A4it8GDD/RCPb82jfE+nQ+:3LfAkiE0oU+xrl700otXDojT5Q+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Malware.AI.2131725873 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3991 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Trojan.ProcessHijack.IyW@ae6uE0ni
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.979f67
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.jlqz
BitDefenderGen:Trojan.ProcessHijack.IyW@ae6uE0ni
NANO-AntivirusTrojan.Win32.AD.efpcjq
MicroWorld-eScanGen:Trojan.ProcessHijack.IyW@ae6uE0ni
Ad-AwareGen:Trojan.ProcessHijack.IyW@ae6uE0ni
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34628.IyW@ae6uE0ni
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Ramnit.hc
FireEyeGeneric.mg.133287a979f678ab
EmsisoftGen:Trojan.ProcessHijack.IyW@ae6uE0ni (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1110160
eGambitUnsafe.AI_Score_100%
MicrosoftVirTool:Win32/Injector.HY
ArcabitTrojan.ProcessHijack.E9C123
ZoneAlarmTrojan-Ransom.Win32.Blocker.jlqz
GDataGen:Trojan.ProcessHijack.IyW@ae6uE0ni
Acronissuspicious
McAfeeArtemis!133287A979F6
MAXmalware (ai score=80)
VBA32BScope.Backdoor.BlackMoon
MalwarebytesMalware.AI.2131725873
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (CLOUD)
IkarusTrojan.Win32.Dynamer
AVGWin32:Malware-gen

How to remove Malware.AI.2131725873?

Malware.AI.2131725873 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment