Malware

Should I remove “Malware.AI.2852537640”?

Malware Removal

The Malware.AI.2852537640 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2852537640 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Malware.AI.2852537640?


File Info:

crc32: 8E79143D
md5: 302c23f845cee6fd256b47ecb4654c1a
name: 302C23F845CEE6FD256B47ECB4654C1A.mlw
sha1: 28a40ffcbab75c3ce4f497fdc30b569699f0c1cc
sha256: 23705da4a0ee545b9f8c6464c4e35b4191cab2b08d994fdaf781165a872c32e5
sha512: 191045aa648e9fdb0fa01a6f88cc854ae840813abcd42137cdd731694784549e33e9fb632e0154f02fd0216aed8fc101958324b1f8a5c52ce6a6e64d41f6276d
ssdeep: 49152:pAI+RLNcdTMy2diE+17EfXYoa43VvaaLvkpz58Fx12JN/0CGNnyJqd:pAI+f3PSclvaykPMx12D0pN02
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: LetyShops Company
FileDescription: LetyShops 2.1 Installation
FileVersion: 2.1
Comments:
CompanyName: LetyShops Company
Translation: 0x0409 0x04e4

Malware.AI.2852537640 also known as:

K7AntiVirusTrojan ( 0053305e1 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ6
ALYacGen:Variant.ClipBanker.215
CylanceUnsafe
SangforTrojan.Win32.AGEN.1004131
AlibabaRansom:Win32/Gandcrab.b0277c7a
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.845cee
CyrenW32/S-8ce49c37!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GGSA
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.ClipBanker.215
NANO-AntivirusTrojan.Win32.Coins.fbvxhj
MicroWorld-eScanGen:Variant.ClipBanker.215
TencentWin32.Trojan.Generic.Lfqa
SophosMal/Generic-R
ComodoMalware@#3q8ldvgatis7t
BitDefenderThetaGen:NN.ZexaF.34294.myW@a4patdoi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.HLLP.vc
FireEyeGen:Variant.ClipBanker.215
EmsisoftGen:Variant.ClipBanker.215 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.eeqmy
AviraHEUR/AGEN.1103318
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.261C575
MicrosoftTrojan:Win32/Occamy.C23
GDataGen:Variant.ClipBanker.215
AhnLab-V3Malware/Win32.Generic.C2523217
McAfeeArtemis!302C23F845CE
MAXmalware (ai score=98)
VBA32BScope.TrojanRansom.GandCrypt
MalwarebytesMalware.AI.2852537640
YandexTrojan.PWS.Coins!9BK/u07xMJE
IkarusTrojan.Win32.Meredrop
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetW32/Coins.ABK!tr.pws
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml

How to remove Malware.AI.2852537640?

Malware.AI.2852537640 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment