Malware

Malware.AI.229129410 information

Malware Removal

The Malware.AI.229129410 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.229129410 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Malware.AI.229129410?


File Info:

name: 6482126E15DEE8234988.mlw
path: /opt/CAPEv2/storage/binaries/120adf0464fdf8fe61092efc4fa8e0d29832922511e52a761c9126f7aba3e0a8
crc32: 3BD965C4
md5: 6482126e15dee8234988e003d1dc8b3b
sha1: 0a0157417a6389d10fdc698fc3f5626d439f5738
sha256: 120adf0464fdf8fe61092efc4fa8e0d29832922511e52a761c9126f7aba3e0a8
sha512: 74a4c57aa1cfb5f89e52a224692c182447f399d0cfb759f2cb3758f3ede344299e7a3be9900d5a16626415aeb7bb533a3625418c126b0046d84b37e6121f959f
ssdeep: 6144:LrjbGb6JaGnvZZtNLdZkRapLmH8c2dnW6:L/bGb6JaGnVNLdZkkpLpc2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12724932A7680F23ED825CAF4392A83A0547DEC3621D6AC17F7C15B15B6F1DABD220753
sha3_384: f075444e939cb31dd8deaeeddd4f8dc36f0641d408d9fcf20a7120f022fbb7bf58ec100eaf2ec048d99d28196c91d17f
ep_bytes: 68243a4000e8eeffffff000000000000
timestamp: 2009-06-07 03:25:50

Version Info:

Translation: 0x0409 0x04b0
ProductName: smfTpuCcwReDdHODdKU
FileVersion: 1.00
ProductVersion: 1.00
InternalName: zYFlejDSNRKyBa
OriginalFilename: zYFlejDSNRKyBa.exe

Malware.AI.229129410 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Sresmon.Gen.1
ClamAVWin.Trojan.Changeup-6169544-0
FireEyeGeneric.mg.6482126e15dee823
McAfeeVBObfus.ba
Cylanceunsafe
VIPREGen:Trojan.Sresmon.Gen.1
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.e15dee
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.VBCrypt.DTW
CyrenW32/Vobfus.V.gen!Eldorado
SymantecW32.Changeup!gen35
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/AutoRun.VB.AKY
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.xabckr
BitDefenderGen:Trojan.Sresmon.Gen.1
NANO-AntivirusTrojan.Win32.VB.covjzt
AvastWin32:VB-AAUX [Trj]
TencentTrojan.Win32.Koobface.p
TACHYONTrojan/W32.VB-Agent.221184.DG
SophosMal/VB-XV
F-SecureWorm.WORM/VBNA.azrc
DrWebTrojan.VbCrypt.60
TrendMicroWORM_VOBFUS.SMAC
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dt
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.Sresmon.Gen.1 (B)
IkarusWorm.Win32.WBNA
AviraWORM/VBNA.azrc
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus.gen!N
XcitiumWorm.Win32.AutoRun.AMH@4owee9
ArcabitTrojan.Sresmon.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmTrojan.Win32.Agent.xabckr
GDataGen:Trojan.Sresmon.Gen.1
GoogleDetected
AhnLab-V3Trojan/Win32.Llac.C149052
Acronissuspicious
BitDefenderThetaAI:Packer.0914CEFE1F
MAXmalware (ai score=84)
VBA32Malware-Cryptor.VB.gen
MalwarebytesMalware.AI.229129410
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMAC
RisingWorm.Vobfus!1.99C7 (CLASSIC)
YandexTrojan.GenAsa!NkcJk7U8aNQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:VB-AAUX [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Malware.AI.229129410?

Malware.AI.229129410 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment