Malware

Should I remove “Malware.AI.258386188”?

Malware Removal

The Malware.AI.258386188 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.258386188 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Accessed credential storage registry keys
  • Deletes executed files from disk
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.258386188?


File Info:

name: 2EEE1ABF4CEF3DFC972D.mlw
path: /opt/CAPEv2/storage/binaries/312613c2e7345f9d4621054006dc80b04624de4b45e611cab37c71b8899ebc85
crc32: 91B9DD54
md5: 2eee1abf4cef3dfc972df6b8429ef3bc
sha1: 1216d5fe3ca26deebb0e1d9e9efc19e1a1891ec0
sha256: 312613c2e7345f9d4621054006dc80b04624de4b45e611cab37c71b8899ebc85
sha512: e895358213bc17814c16c4ea5a6f4a4c0a60c759e222d1127ffbf128aebbc9c3c8e8e0d85ae3d652a0f1234547893ec641d4dc03d046fcd3eaa3aec892a4a458
ssdeep: 6144:UNjAZOiPFeoJipVP3ARnq3srCVLkzNr+edUqW9jMV5btlVSzwmt2Hx:kMjEoJiPAC+CVgB5dUqW9oV5bX4zeR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1566402533BE6D1FAE0E201718D926BA56DBDE6740728C6C3B7900A066E357D1D63E383
sha3_384: 899bf7decb88895a5a3d27d3f83cfbd03377104130002327ab3c70cd9bb254b7afb2f7da8c6a8bcb1a6a68d6a2cbb0a8
ep_bytes: 558bec6aff6860a0410068506a410064
timestamp: 2012-12-30 08:50:02

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.5.0.2712
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.5.0.2712
Translation: 0x0000 0x04b0

Malware.AI.258386188 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Inject.1b!c
DrWebTrojan.Boaxxe.484
MicroWorld-eScanDropped:Trojan.GenericKD.3550753
ClamAVWin.Trojan.Bunitu-7394346-1
FireEyeGeneric.mg.2eee1abf4cef3dfc
CAT-QuickHealRansom.Locky.A
McAfeeArtemis!2EEE1ABF4CEF
Cylanceunsafe
SangforDropper.Win32.Inject.Vl6t
K7AntiVirusTrojan ( 0055e3f51 )
AlibabaVirTool:Win32/CeeInject.89fd0239
K7GWTrojan ( 0055e3f51 )
Cybereasonmalicious.f4cef3
BitDefenderThetaGen:NN.ZexaF.36250.gy3@a0uktpaO
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Inject.abggu
BitDefenderDropped:Trojan.GenericKD.3550753
NANO-AntivirusTrojan.Dos.Code.egouws
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Inject.Zchl
EmsisoftDropped:Trojan.GenericKD.3550753 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREDropped:Trojan.GenericKD.3550753
TrendMicroRansom_CERBERENC.SMNS4
McAfee-GW-EditionGeneric.amv
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious SFX
GDataDropped:Trojan.GenericKD.3550753
JiangminTrojan.Yakes.rwe
WebrootW32.Inject.abggu
AviraHEUR/AGEN.1313421
Antiy-AVLTrojan[Backdoor]/Win32.Hlux
XcitiumTrojWare.Win32.Matsnu.C@6lh75k
ArcabitTrojan.Generic.D362E21
ZoneAlarmTrojan.Win32.Inject.abggu
MicrosoftTrojan:Win32/Ditertag.A
GoogleDetected
VBA32Trojan.Inject
ALYacDropped:Trojan.GenericKD.3550753
MAXmalware (ai score=100)
MalwarebytesMalware.AI.258386188
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBERENC.SMNS4
RisingDropper.Bunitu!8.A59 (TFE:3:mTLRGqOuilU)
IkarusTrojan.NSIS.Injector
MaxSecureTrojan.Malware.9950683.susgen
FortinetNSIS/Injector.AOW!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.258386188?

Malware.AI.258386188 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment