Malware

Malware.AI.198031622 (file analysis)

Malware Removal

The Malware.AI.198031622 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.198031622 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.198031622?


File Info:

name: 4FD919CD6FBED243823E.mlw
path: /opt/CAPEv2/storage/binaries/27855470ae0b367c69a70a5f9eb3c6d7f3e5217828a74c5f8549365a3be1b30a
crc32: 10D29F15
md5: 4fd919cd6fbed243823e0bcdecadad06
sha1: 257b376cadada02e4372956a5a89136e022347a7
sha256: 27855470ae0b367c69a70a5f9eb3c6d7f3e5217828a74c5f8549365a3be1b30a
sha512: ad5d85d332e9caf4dd8797048dd807b77b64df765163d1108c4b032f3e5c10bcfe301356e37ce913ac24c544835d04a6dc47c0c43b32ee978dd79c538a39e8b2
ssdeep: 3072:5gmgc60aKSCTMr+g04JgnTwRHEk1uEnkFgO3WKP6q+p:5Br6lDCTzgFJg+nKSq+p
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FC36C1174C0C072E9B75A3149BCDAA55ABDFD300B245AE773D8027E8F745E0AA36A73
sha3_384: 81de0140a7372935f98ca913f2d3173e6d3bfabd1c1de7b6ba12cb278b66b99090ed05d4c7c4b2c25d54e5e32c65e094
ep_bytes: e8df040000e980feffff558bec6a00ff
timestamp: 2017-10-05 15:01:08

Version Info:

OriginalFilename: Traetum Strobe.exe
ProductVersion: 2.3.3.9
Translation: 0x0409 0x04b0

Malware.AI.198031622 also known as:

Elasticmalicious (high confidence)
CylanceUnsafe
ZillyaDownloader.Tovkater.Win32.489
SangforTrojan.Win32.Tovkater.EQ
K7AntiVirusTrojan-Downloader ( 00518a0a1 )
AlibabaTrojanDownloader:Win32/Tovkater.e670dd54
K7GWTrojan-Downloader ( 00518a0a1 )
Cybereasonmalicious.d6fbed
CyrenW32/Tovkater.P.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Tovkater.EQ
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Tovkater.b
NANO-AntivirusTrojan.Win32.InstallMonster.etkanm
AvastWin32:Malware-gen
TencentWin32.Trojan-downloader.Tovkater.Pikn
ComodoApplication.Win32.InstallMonster.DX@7e9j3l
DrWebTrojan.InstallMonster.2392
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OJ921
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.ch
FireEyeGeneric.mg.4fd919cd6fbed243
SophosMal/Generic-S (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Tovkater.e
WebrootW32.Malware.Gen
AviraADWARE/InstMonster.Gen7
Antiy-AVLTrojan/Win32.TSGeneric
GridinsoftRansom.Win32.Occamy.oa!s1
ViRobotTrojan.Win32.Z.Tovkater.121344
MicrosoftTrojan:Win32/Occamy.C27
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Abnores.R211818
McAfeeRDN/Generic Downloader.x
MAXmalware (ai score=100)
VBA32BScope.Trojan.InstallMonster
MalwarebytesMalware.AI.198031622
TrendMicro-HouseCallTROJ_GEN.R002C0OJ921
RisingDownloader.Tovkater!8.E5CE (CLOUD)
YandexTrojan.GenAsa!ADmX2wa0n20
IkarusTrojan-Downloader.Win32.Tovkater
eGambitUnsafe.AI_Score_91%
FortinetW32/Tovkater.FQ!tr
BitDefenderThetaGen:NN.ZexaF.34114.hy0@aqW4RZdi
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.198031622?

Malware.AI.198031622 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment