Malware

What is “Malware.AI.2956702997”?

Malware Removal

The Malware.AI.2956702997 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2956702997 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Malware.AI.2956702997?


File Info:

name: 0292D9C96EBB295E740E.mlw
path: /opt/CAPEv2/storage/binaries/4266886a336d75b0d17c6b0be00ebd1f784ba1a85ecfd02fba86cc0f2252be91
crc32: 67BAB8CD
md5: 0292d9c96ebb295e740eb8576c0b16fb
sha1: 8dcc9183f9746237ffb7e9837ac838e01c5f2c76
sha256: 4266886a336d75b0d17c6b0be00ebd1f784ba1a85ecfd02fba86cc0f2252be91
sha512: a69dc1cdaa544b07c8cbf59e9ed0737e9d5b9659959d72c91815cf97d5637c84547a2bf2830ad5fc0bc2f46b51bf45906047dd55391eef98c9ef8ffc0bd3ae6e
ssdeep: 49152:bsu8P+/4tkT3a6KlcJ7BeIeKOdE+bE6Nsip1mNly/2W0myH5V+iq93:Yu8G/zTq1lcJMI4fbERI1mNk/2W0mEs9
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T115C5238774CF0DEDF646C6B341A6BC7860A275311FAAC51D3AE6DD92338ACD99200727
sha3_384: 40f72e1aecf6ab7001703365c5438c15ea34b0fd755356a570d8c39337ffd8d19917680b5cf34d2e748790bd351a1214
ep_bytes: eb0841ef020000000000e94521fdff48
timestamp: 2021-12-08 20:28:52

Version Info:

0: [No Data]

Malware.AI.2956702997 also known as:

LionicTrojan.Win32.StartPage.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38234680
FireEyeGeneric.mg.0292d9c96ebb295e
ALYacTrojan.GenericKD.38234680
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000001d1 )
AlibabaPacked:Win32/VMProtect.f46dba51
K7GWTrojan ( 7000001d1 )
Cybereasonmalicious.3f9746
CyrenW64/Razy.FF.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Packed.VMProtect.AB
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Vmprotect-6824127-0
KasperskyVHO:Trojan.Win32.StartPage.gen
BitDefenderTrojan.GenericKD.38234680
AvastWin64:TrojanX-gen [Trj]
Ad-AwareTrojan.GenericKD.38234680
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PLC21
McAfee-GW-EditionBehavesLike.Win64.Dropper.vc
EmsisoftTrojan.GenericKD.38234680 (B)
IkarusTrojan.Win32.VMProtect
AviraTR/Black.Gen2
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.34EB6C6
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Ymacco.AB42
GDataTrojan.GenericKD.38234680
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.GV.C4830716
Acronissuspicious
McAfeePacked-GV!0292D9C96EBB
VBA32Trojan.StartPage
MalwarebytesMalware.AI.2956702997
TrendMicro-HouseCallTROJ_GEN.R002C0PLC21
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_60%
FortinetW32/Packed.GV!tr
AVGWin64:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.2956702997?

Malware.AI.2956702997 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment