Malware

Malware.AI.2737955140 removal tips

Malware Removal

The Malware.AI.2737955140 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2737955140 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Malware.AI.2737955140?


File Info:

name: 88D2A993BD3AB61A4D12.mlw
path: /opt/CAPEv2/storage/binaries/7c15b8726df71ad5a978787afbce226d905b7e6f494a8b60059f0d3ea4dc9b45
crc32: 55FD0901
md5: 88d2a993bd3ab61a4d12cd9deeaa3fb1
sha1: e993556b09ac70f7c863974af7ef1b873f643f4c
sha256: 7c15b8726df71ad5a978787afbce226d905b7e6f494a8b60059f0d3ea4dc9b45
sha512: f399d9f9c2307d6c4bb5c15be434352ba535664045fce0853b8d9496bbd44d1983d3a9f13572d8986acf878e0fb81adc7fcf5e06d77e71259fe110f1d388411e
ssdeep: 98304:ET2zzjMMeWN2NCWC8Y22uske41PPUrIE//LhFCx43tWM:ET2zzjMMeWN2QjWhPUrNna4dWM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19036BE13B685C0B2E48A067952B2673E1D75A7200735D9C3FFE42DA56E701E2973E38E
sha3_384: 08aafd7105983a2fcbd9fa66b2cab596f92ac935ba9ea21c44ad0a511a676766fd4f7d808e82144b08515783a4912010
ep_bytes: 558bec6aff68b80c4a0068c4ec480064
timestamp: 2021-09-04 03:53:33

Version Info:

FileVersion: 5.8.0.288
FileDescription: YXUpdate
ProductName: YXUpdate
ProductVersion: 5.8.0.288
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: YXUpdate
Translation: 0x0804 0x04b0

Malware.AI.2737955140 also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.62209422
FireEyeGeneric.mg.88d2a993bd3ab61a
CAT-QuickHealTrojan.Antavmu.9366
ALYacTrojan.GenericKD.62209422
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.154682
SangforTrojan.Win32.Agent.V659
K7AntiVirusTrojan ( 005512061 )
BitDefenderTrojan.GenericKD.62209422
Cybereasonmalicious.b09ac7
BitDefenderThetaGen:NN.ZexaF.34682.@t0@ayeX9Kcb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.DLTY
TrendMicro-HouseCallTROJ_GEN.R002H0CIK22
Paloaltogeneric.ml
ClamAVWin.Malware.Trojanx-9958847-0
AlibabaTrojan:Win32/GenKryptik.b09d0cf2
CynetMalicious (score: 100)
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKD.62209422
SophosMal/Generic-S
VIPRETrojan.GenericKD.62209422
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.62209422 (B)
IkarusTrojan.Win32.Crypt
AviraHEUR/AGEN.1227841
Antiy-AVLTrojan/Generic.ASCommon.223
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D3B53D8E
GDataWin32.Trojan.PSE.1DPEYYJ
GoogleDetected
McAfeeArtemis!88D2A993BD3A
MAXmalware (ai score=85)
VBA32BScope.Trojan.Inject
MalwarebytesMalware.AI.2737955140
TencentWin32.Trojan.Agen.Ztjl
SentinelOneStatic AI – Suspicious PE
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.2737955140?

Malware.AI.2737955140 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment