Malware

Malware.AI.2628756999 removal

Malware Removal

The Malware.AI.2628756999 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2628756999 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.2628756999?


File Info:

name: 7B5D18726017D623D5B4.mlw
path: /opt/CAPEv2/storage/binaries/6d8d77093e5ab5d2e490a9f1a853c7fb1e873e20e354f8c51475de4e523b1903
crc32: 588F15C3
md5: 7b5d18726017d623d5b4d6cbf2946806
sha1: b42fa8154c2c44a492fd38f2e8f7e68339dbee21
sha256: 6d8d77093e5ab5d2e490a9f1a853c7fb1e873e20e354f8c51475de4e523b1903
sha512: 9b59a91dc14dee8a5191297b94de23e4c93ead5905f2adc04982a1066befce99c4b4a8f1b6fb75c28729b190967822f8abb078da3d274b8724cc041b39755df4
ssdeep: 24576:O6jzeqsZphGlYwv60hPCl8l4ao4jAzUgDsZaBJFuxdgSpqaanfACH3:O0zeVZphTwS0hPCI4DmA4usIvExd33ax
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13165230AB4448F55E52F063CBE0B182EDD88AC4A1305C9FA6BF47F3E64F1650B55A3DA
sha3_384: 04f1349d806f3736d24687f50e138d1067850d966bb70240fb8bbaed86b731bb7cb03e7a2ce9dafca0db67a9f107d282
ep_bytes: 81eab30adc7d4881fa9337455ac1ee96
timestamp: 2010-04-03 14:10:27

Version Info:

FileVersion: 1.0.0.0
FileDescription:
ProductName:
ProductVersion: 1.0.0.0
CompanyName:
LegalCopyright:
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Malware.AI.2628756999 also known as:

BkavW32.AIDetect.malware2
FireEyeGeneric.mg.7b5d18726017d623
McAfeeArtemis!7B5D18726017
MalwarebytesMalware.AI.2628756999
K7AntiVirusTrojan ( 002994e21 )
K7GWTrojan ( 002994e21 )
Cybereasonmalicious.54c2c4
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.PrivateEXEProtector.C suspicious
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaPacked:Win32/PrivateEXEProtector.9d2012cf
NANO-AntivirusTrojan.Win32.Mlw.hhfvtr
TencentWin32.Trojan.Generic.Aisj
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Worm.tc
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
IkarusPUA.PrivateexeProtector
GDataWin32.Application.PUPStudio.A
JiangminTrojan/Yakes.hiu
AviraTR/Crypt.XPACK.Gen2
MicrosoftPWS:Win32/Zbot!ml
BitDefenderThetaGen:NN.ZexaF.34742.Ar0@aymX3ujb
VBA32BScope.Trojan.Downloader
PandaTrj/CI.A
RisingTrojan.Generic@AI.100 (RDMK:X62Vtmzy6gCIROZlYi462g)
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/Generic
AVGFileRepMalware [Misc]
AvastFileRepMalware [Misc]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2628756999?

Malware.AI.2628756999 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment