Malware

Malware.AI.2912380186 (file analysis)

Malware Removal

The Malware.AI.2912380186 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2912380186 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2912380186?


File Info:

name: 580A36097F91ABBD712E.mlw
path: /opt/CAPEv2/storage/binaries/885fa86eb7db77eeb81af6fc9cae9516c22c6440ab2ed8af159089899faaeed4
crc32: 725027B7
md5: 580a36097f91abbd712e6bfa3934e5b3
sha1: 1faf51ff9ffc7db6f22bf55ca8c24970b8a6c1f3
sha256: 885fa86eb7db77eeb81af6fc9cae9516c22c6440ab2ed8af159089899faaeed4
sha512: d8fd8f68744817c56b76e1d28c7be6fac57ce319131b31691d0ace505e513ee5835d1c64e127f3591bc5a0449d2d068014c7f1df29f2ce02e77b48e5c86a43ea
ssdeep: 12288:7rGHyLZ8QLME0hw2tDOsSyhAB68UPifywRUCKOfQzBEvkkSpC/tk:7rGSSJxEyhAzLkWQtEvk5CG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18BF401C3D33A0CD8E6621E35D0B3D2E063E2DD1725235A825B347869CBB22776D7B256
sha3_384: 8b4f7eabdb6537af62abe3c12f0272c24469708e0fc86cb4bde79922576f007296bcb77721d1f854934b0047f35fc8bd
ep_bytes: 60e80000000058059f0200008b3003f0
timestamp: 2022-06-11 11:07:09

Version Info:

Comments:
CompanyName: TubeMate Software
FileDescription: TubeMate Player
FileVersion: 3, 27, 11, 0
InternalName: TubeMate Player
LegalCopyright: (C) TubeMate Software. All rights reserved.
LegalTrademarks:
OriginalFilename: TubeMatePlayer.EXE
PrivateBuild:
ProductName: Windows TubeMate
ProductVersion: 3, 27, 11, 0
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.AI.2912380186 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Vtflooder.lnTD
ClamAVWin.Malware.Generic-9951960-0
FireEyeGeneric.mg.580a36097f91abbd
Cylanceunsafe
SangforTrojan.Win32.Agent.Vhhj
CrowdStrikewin/malicious_confidence_70% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
SUPERAntiSpywareTrojan.Agent/Generic
SophosGeneric Reputation PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Win32.SGeneric
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R483072
McAfeeGenericRXAA-FA!580A36097F91
MalwarebytesMalware.AI.2912380186
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.36350.Um0@a8bT0hmi
DeepInstinctMALICIOUS

How to remove Malware.AI.2912380186?

Malware.AI.2912380186 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment