Malware

Should I remove “Malware.AI.28851552”?

Malware Removal

The Malware.AI.28851552 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.28851552 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Detects VMware through the presence of a registry key

How to determine Malware.AI.28851552?


File Info:

name: 275A078C63793F7BD6C9.mlw
path: /opt/CAPEv2/storage/binaries/31489e3190405b6d2281beb6ce48dc2134afc40c3df9f5b166e029b168680360
crc32: C324D374
md5: 275a078c63793f7bd6c9860b18693f9d
sha1: 5a5cebc009b4f8137733562f0b5debc52aba1f1c
sha256: 31489e3190405b6d2281beb6ce48dc2134afc40c3df9f5b166e029b168680360
sha512: 0c1216eae4a24da68643d301e2fb2850aa357e0a8d1de8bc47c5b13a13cb9f80a368aa5a97e21fcd3def18943619875762b0911cb997f94e3d677be9e8dbaf62
ssdeep: 1536:IEkV6sNskJIcsVI+hw96Z543kbvn1TtXXnXX4IofadD73YFWTKjfa1J+cHWtDjCk:vgz9sV28Z5SkjnbXXHIfyInCL+cHciC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12AE3CF5FD0169F37CC789AB29B7A904AA72C130DAB4F2B2F142CD168B4D74051BCB26C
sha3_384: e0625476f700203fa2448e895e4b0739cb0c1fcbbd551ba57ea956027ce6700dbb85e94094de501be03b393d0fe3aa64
ep_bytes: 60be001042008dbe0000feff5783cdff
timestamp: 1970-01-01 15:30:08

Version Info:

0: [No Data]

Malware.AI.28851552 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Sdbot.7021C09F
FireEyeGeneric.mg.275a078c63793f7b
McAfeeArtemis!275A078C6379
CylanceUnsafe
ZillyaBackdoor.GTbot.Win32.124
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0051918e1 )
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.c63793
BaiduWin32.Backdoor.Aebot.f
CyrenW32/Mywebsearch.F.gen!Eldorado
SymantecBackdoor.Abebot
Elasticmalicious (high confidence)
ESET-NOD32Win32/Aebot.K
APEXMalicious
KasperskyBackdoor.Win32.GTbot.c
BitDefenderGeneric.Sdbot.7021C09F
NANO-AntivirusTrojan.Win32.GTbot.craqxn
AvastWin32:BotX-gen [Trj]
TencentMalware.Win32.Gencirc.11fb46ef
Ad-AwareGeneric.Sdbot.7021C09F
SophosMal/Generic-S
ComodoTrojWare.Win32.Aebot.EF@4ye0hx
DrWebBackDoor.IRC.Sdbot.based
VIPREGeneric.Sdbot.7021C09F
TrendMicroWORM_SDBOT.GEN-1
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
EmsisoftGeneric.Sdbot.7021C09F (B)
SentinelOneStatic AI – Malicious PE
GDataGeneric.Sdbot.7021C09F
JiangminBackdoor/GTbot.bj
AviraTR/Downloader.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Win32/IRCBot.worm.Gen
Acronissuspicious
BitDefenderThetaAI:Packer.2B36C5541D
ALYacGeneric.Sdbot.7021C09F
MAXmalware (ai score=85)
VBA32BScope.Backdoor.Win32.SdBot
MalwarebytesMalware.AI.28851552
TrendMicro-HouseCallWORM_SDBOT.GEN-1
RisingBackdoor.GTbot!8.2EC3 (CLOUD)
YandexTrojan.Lineage.Gen!Pac.3
IkarusBackdoor.Win32.Aebot.B
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Aebot.K!tr
AVGWin32:BotX-gen [Trj]
PandaW32/Gaobot.AZM.worm
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.28851552?

Malware.AI.28851552 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment