Malware

Malware.AI.250608084 removal

Malware Removal

The Malware.AI.250608084 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.250608084 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Malware.AI.250608084?


File Info:

name: 5B0959B38229F4DC72EA.mlw
path: /opt/CAPEv2/storage/binaries/25c476cbcb7fa8f4724e8aba4b6dbfd77d61b2f6200cf8f5746b4f02de9dbe2d
crc32: 080357B3
md5: 5b0959b38229f4dc72ea776e1ad79dbf
sha1: 0b705d52d6821c9d647d22a8167faee4e70460e2
sha256: 25c476cbcb7fa8f4724e8aba4b6dbfd77d61b2f6200cf8f5746b4f02de9dbe2d
sha512: f1c7fc45c69eb8465da989d6d4242378bf62f01ac0b6dd6372c0cdcef43848e4614629e38a2271f4ec569cc5dd50e74adcd16900915f44c43fdbcd5a4d40eaf4
ssdeep: 3072:yn10AV+j62uiqR/omVq+0996E/GBDph63+m9W6HMRmVrynarATrgpBtJHSZ2dsjx:yncuXiqRAmV3bE/G15mA6wnasTrotpF8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A04129397DDC738F46D6235408E6E25EAF8C78264E103A5A47A5A1D2D0C208BF2E537
sha3_384: b29219a5f206448685ad0df49a8e7282176fe76350d6493db98f96c182d4634273ca1a67e90741784852939e507b8d94
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: uusee
FileDescription:
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

Malware.AI.250608084 also known as:

LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.62219059
ClamAVWin.Trojan.Agent2-39
FireEyeTrojan.GenericKD.62219059
ALYacTrojan.GenericKD.62219059
CylanceUnsafe
ZillyaTrojan.Agent2.Win32.12446
SangforTrojan.Win32.Chinflej.Vohr
K7AntiVirusTrojan ( 00285f811 )
BitDefenderTrojan.GenericKD.62219059
K7GWTrojan ( 00285f811 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.ACBT
CyrenW32/Delf.AV.gen!Eldorado
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Chinflej.AK
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Chinflej.a57422f6
NANO-AntivirusTrojan.Win32.Agent.dgfhr
ViRobotTrojan.Win32.A.Agent.184320[ASPack]
RisingTrojan.Win32.Fednu.aiv (CLASSIC)
Ad-AwareTrojan.GenericKD.62219059
EmsisoftTrojan.GenericKD.62219059 (B)
ComodoTrojWare.Win32.Agent2.dffq@4hugbx
DrWebTrojan.Siggen3.33734
VIPRETrojan.GenericKD.62219059
TrendMicroTROJ_AGENT_032869.TOMB
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
JiangminTrojan/Agent.fzkp
WebrootW32.Trojan.Gen
AviraTR/Agent.hgoo
Antiy-AVLTrojan/Generic.ASMalwS.11D
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D3B56333
GDataTrojan.GenericKD.62219059
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R16473
MAXmalware (ai score=82)
VBA32Trojan.Agent2
MalwarebytesMalware.AI.250608084
PandaGeneric Malware
TrendMicro-HouseCallTROJ_AGENT_032869.TOMB
TencentMalware.Win32.Gencirc.10b62adb
YandexTrojan.GenAsa!8WBoZ10Bdms
FortinetW32/Chinflej.AK!tr
BitDefenderThetaGen:NN.ZelphiF.34682.lO0ba880Whkb
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.2d6821
AvastWin32:Evo-gen [Trj]

How to remove Malware.AI.250608084?

Malware.AI.250608084 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment