Malware

What is “Malware.AI.2852902010”?

Malware Removal

The Malware.AI.2852902010 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2852902010 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Sniffs keystrokes
  • Network activity detected but not expressed in API logs

How to determine Malware.AI.2852902010?


File Info:

crc32: 71B96D21
md5: f36333b33333b272ad4be6ce1aa7b00b
name: F36333B33333B272AD4BE6CE1AA7B00B.mlw
sha1: 849c63cad142393b9fc5814c218bf149f232d311
sha256: 7bc7c7ec925e8bb676dadafc21e80aadebb19459abe01882760d292fd8406001
sha512: bdeb23f199e0bc11bec6d106cf0db83509af5c65d80c448dff259c5bbc1dcba39d1180e916ed281b7107c10a5f0a485f0a056533e0ecc4b0acf03f80686c77d2
ssdeep: 24576:/phZY1EUBH64MvjpP1KaWugkhPG44B04SpKiRtFxpoXFNIE:/ps1qjRWrkhPG7BPuKiRtFxiX0E
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Danalex516cx53f8x7248x6743x6240x6709
InternalName: DanaCMS.exe
FileVersion: %Version%
CompanyName: x6df1x5733x5e02x5927x62ffx79d1x6280x6709x9650x516cx53f8
ProductName: DanaCMS
ProductVersion: V4.1.8
FileDescription: DanaCMS
OriginalFilename: DanaCMS.exe
Translation: 0x0804 0x04b0

Malware.AI.2852902010 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Wsgame.48182
CynetMalicious (score: 99)
CAT-QuickHealTrojan.MauvaiseRI.S5248404
ALYacTrojan.Generic.22061892
CylanceUnsafe
ZillyaAdware.OutBrowse.Win32.67508
AlibabaTrojanPSW:Win32/BScope.463cb50d
Cybereasonmalicious.33333b
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-1376602
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Generic.22061892
NANO-AntivirusTrojan.Win32.GenericKD.eqraqe
MicroWorld-eScanTrojan.Generic.22061892
Ad-AwareTrojan.Generic.22061892
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.mnKfa4VZazgH
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXBA-LF!FA5A2B583F4D
FireEyeGeneric.mg.f36333b33333b272
EmsisoftTrojan.Generic.22061892 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Agent.flbz
AviraHEUR/AGEN.1101745
Antiy-AVLTrojan/Generic.ASMalwS.18376DE
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.19Q2126
McAfeeArtemis!F36333B33333
MAXmalware (ai score=87)
VBA32BScope.Trojan.Tiggre
MalwarebytesMalware.AI.2852902010
PandaTrj/Genetic.gen
RisingTrojan.Injector!1.A1C3 (CLASSIC)
FortinetGenericRXBA.LF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Malware.AI.2852902010?

Malware.AI.2852902010 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment