Malware

About “Malware.AI.2770315892” infection

Malware Removal

The Malware.AI.2770315892 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2770315892 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Malware.AI.2770315892?


File Info:

name: E5FA1E1373DF6A3F6FEE.mlw
path: /opt/CAPEv2/storage/binaries/5493873f3633fa6340aac4057d5f09bd9f3eed281956f5fef4cbb6e0524277c0
crc32: F5AC3E40
md5: e5fa1e1373df6a3f6feeea4d13b107db
sha1: 8f35ab0a1675fe747e8873248a300f5af0f6054d
sha256: 5493873f3633fa6340aac4057d5f09bd9f3eed281956f5fef4cbb6e0524277c0
sha512: 639636632772d3798488d8a9519e4c9bdef1d1f47be12250e299606738f81e88892a225cc500e946a1fb357bcfc9761274153f981e1c7a99a6421eeaa08a67b5
ssdeep: 6144:wrmA8UerTuD1xsuKTDjGHr/yYmeiOzTEohv6Tn/OgzEN5IV:wf8Uer6D1xijGeYPiQI2vm/OgO5IV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123D5BF02B2D150BED0AA513054B69F369ABDFD034633AA4B977CFE5E1E31781D62930E
sha3_384: 384a867b5882388901fb1a4e9d1c1ad684397a4417564421dcac38c3713b472f72dff45152fdb5733ccf68b9f77a4dbc
ep_bytes: 558bec6aff68f8786800688872670064
timestamp: 2006-02-01 23:02:14

Version Info:

Comments:
CompanyName: Sysinternals - www.sysinternals.com
FileDescription: Rootkit detection utility
FileVersion: 1.70
InternalName:
LegalCopyright: Copyright (C) 2005-2006 Bryce Cogswell and Mark Russinovich
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName: Sysinternals Rootkitrevealer
ProductVersion: 1.70
SpecialBuild:
Translation: 0x0409 0x04b0

Malware.AI.2770315892 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Swisyn.4!c
FireEyeGeneric.mg.e5fa1e1373df6a3f
CAT-QuickHealTrojan.Swisyn.OD5
CylanceUnsafe
SangforTrojan.Win32.Agent.Vq4d
Cybereasonmalicious.a1675f
CyrenW32/Swisyn.R.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Swisyn-6888356-0
NANO-AntivirusTrojan.Win32.TrjGen.czkqzz
AvastWin32:Malware-gen
ZillyaTrojan.Swisyn.Win32.28546
McAfee-GW-EditionBehavesLike.Win32.BadFile.vz
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Swisyn
GDataWin32.Trojan.PSE.1Q2SFK3
Antiy-AVLTrojan/Generic.ASMalwS.330C
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!E5FA1E1373DF
VBA32Trojan.Swisyn
MalwarebytesMalware.AI.2770315892
TrendMicro-HouseCallTROJ_GEN.R002H0CG522
RisingTrojan.Generic@AI.94 (RDMK:ONlRVNtyB1BU2EaAnKSd4g)
YandexTrojan.Vilsel!z3Dn+i2Zrgw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Swisyn.R!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2770315892?

Malware.AI.2770315892 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment