Malware

Malware.AI.367200927 removal

Malware Removal

The Malware.AI.367200927 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.367200927 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Malware.AI.367200927?


File Info:

name: EDCE52FB71CC0B51F561.mlw
path: /opt/CAPEv2/storage/binaries/54caedd5493a49fcbfadc82e9a9f0ecda6697ae8392a852070aa7306a42b861b
crc32: E2A04304
md5: edce52fb71cc0b51f561cd6e2f7d3e5f
sha1: 11e6fd67d9c8d30aa8ebf653a4a07fabfeb1f256
sha256: 54caedd5493a49fcbfadc82e9a9f0ecda6697ae8392a852070aa7306a42b861b
sha512: 4bcb2fff04d6f382ecbebac83ec4d685a46ab18b83644927af01868655fc31123a29f3b257c063846380b63505313d38bdda3152e9bf2d169c3c5f3ab93f0057
ssdeep: 24576:UAHnh+eWsN3skA4RV1Hom2KXMmHapw25:jh+ZkldoPK8YapF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144057B0273D2D036FFAB92739B6AB20596BD79250133852F13981DB9BD701B1273E663
sha3_384: 9d5576c1faf595c15111b60070032b98cec6856b8036bbc5018c6d284bb127e373eba13a7d8e9de6d43dca501ed27ff4
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-06-28 02:09:24

Version Info:

Comments: dXNDFGnVHB
CompanyName: YbhOxDVoJcMewjJKycCoD
FileDescription: jfRr
FileVersion: 79.64.6.37
InternalName: CuxsQBi
LegalCopyright: gpiTha
LegalTrademarks: lndpX
ProductName: ewGd
ProductVersion: 56.96.25.2
Translation: 0x0809 0x04b0

Malware.AI.367200927 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Trojan.Heur.KT.2.Zu0@a0IwC0oi
FireEyeGen:Trojan.Heur.KT.2.Zu0@a0IwC0oi
ALYacGen:Trojan.Heur.KT.2.Zu0@a0IwC0oi
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 0056a9891 )
K7GWTrojan ( 0056a9891 )
Cybereasonmalicious.b71cc0
CyrenW32/AutoIt.SR.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Autoit.OHY
APEXMalicious
KasperskyUDS:Trojan.Script.Generic
BitDefenderGen:Trojan.Heur.KT.2.Zu0@a0IwC0oi
AvastAutoIt:Runner-BH [Trj]
Ad-AwareGen:Trojan.Heur.KT.2.Zu0@a0IwC0oi
EmsisoftGen:Trojan.Heur.KT.2.Zu0@a0IwC0oi (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-R
IkarusTrojan.Win32.Autoit
GDataGen:Trojan.Heur.KT.2.Zu0@a0IwC0oi
AviraWORM/FakeExt.Gen8
ArcabitTrojan.Heur.KT.2.EBA0AB
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeW32/Autorun.worm.aakf
MAXmalware (ai score=87)
MalwarebytesMalware.AI.367200927
RisingTrojan.Runner/Autoit!1.C11B (CLASSIC)
FortinetW32/Autoit.OHL!tr
BitDefenderThetaAI:Packer.69AB7BE821
AVGAutoIt:Runner-BH [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Malware.AI.367200927?

Malware.AI.367200927 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment