Malware

What is “Malware.AI.2000820001”?

Malware Removal

The Malware.AI.2000820001 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2000820001 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Malware.AI.2000820001?


File Info:

name: C4E8AB4CED24924690DC.mlw
path: /opt/CAPEv2/storage/binaries/b9ffafc5b9c6003dcb899e24f087d9c7c6212881508fd76a9576eea97808099c
crc32: 7F921DE0
md5: c4e8ab4ced24924690dcc02ec04b7e40
sha1: d66d855ecedfd09f10375fd231bb689084415fd2
sha256: b9ffafc5b9c6003dcb899e24f087d9c7c6212881508fd76a9576eea97808099c
sha512: 6e4e2cc296911208a6b75f6047f758e38f5bd981fadf075e813bc778bb41efce749fdd9904b50bb7af7c71944d1e8fc28008252f3dd8d587d4fdf71d62496ea3
ssdeep: 49152:czYt11/GxFqFLcmZh1KP33LffcX2xgeUjxFBS977ReaCLzqyKTeIPii/urvUS:gMGxcxcmZQ3TfY2meSDSB7ReDLzRKTep
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BAD533BFC5B68295F1F6D878F62FA5A16111353B0D905A3ABF02C1EBC6B39E406D011B
sha3_384: 23841fc58f5576c09d8ea1eca01a3199996de3004d16b016b7742c4f39ab928c753c105e3be7ae77fabd5d8303c1ab60
ep_bytes: 60be0040a0008dbe00d09fff5783cdff
timestamp: 2021-12-30 06:38:10

Version Info:

FileVersion: 1.0.0.0
FileDescription: By 暖心 QQ:1253659669
ProductName: 暖心社区一键配置器
ProductVersion: 1.0.0.0
CompanyName: 暖心
LegalCopyright: 本站游戏仅限休闲娱乐、学习研究! 请勿用于其他商业用途及违法行为! 因此产生的一切后果自行承担,与本网站无关! 下载本站资源应在下载资源的24小时之内删除!
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Malware.AI.2000820001 also known as:

LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PWSIME.2
FireEyeGeneric.mg.c4e8ab4ced249246
ALYacGen:Heur.PWSIME.2
CylanceUnsafe
SangforTrojan.Win32.Yakes.abble
K7AntiVirusAdware ( 00506e8d1 )
AlibabaTrojan:Win32/Yakes.15f537bb
K7GWAdware ( 00506e8d1 )
Cybereasonmalicious.ced249
BitDefenderThetaGen:NN.ZexaF.34182.3oKfai3Uh5ab
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecTrojan.KillAV
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0DB422
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9779041-0
KasperskyTrojan.Win32.Yakes.abble
BitDefenderGen:Heur.PWSIME.2
AvastFileRepMalware
TencentWin32.Trojan.Killav.Taey
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0DB422
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Heur.PWSIME.2 (B)
IkarusTrojan.Win32.FlyAgent
eGambitUnsafe.AI_Score_100%
AviraTR/AVKill.cswwo
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Avkill.E
ZoneAlarmTrojan.Win32.Yakes.abble
GDataWin32.Application.PUPStudio.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Avkill.C4865485
McAfeeGenericRXAA-AA!C4E8AB4CED24
VBA32BScope.Trojan.Download
MalwarebytesMalware.AI.2000820001
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
MAXmalware (ai score=80)
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.65CA!tr
AVGFileRepMalware
PandaTrj/GdSda.A

How to remove Malware.AI.2000820001?

Malware.AI.2000820001 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment