Malware

Malware.AI.2976085798 (file analysis)

Malware Removal

The Malware.AI.2976085798 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2976085798 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family

How to determine Malware.AI.2976085798?


File Info:

name: 3023594DC5C5220B553C.mlw
path: /opt/CAPEv2/storage/binaries/201b51ac598f7039acad2f9f004368346043113648d3a51440c41368d501df16
crc32: ACF60971
md5: 3023594dc5c5220b553c74e4950385bc
sha1: 8c34ec6bdab633e42a895fc83ec06a33585410df
sha256: 201b51ac598f7039acad2f9f004368346043113648d3a51440c41368d501df16
sha512: 0210826ddb490b72211f2477797e314a0a2a99a5a6db1303e646b8159ed80b1ff1fc22e77c5a7435dda370f4a40e9b78de28a7d88be27af8d0951b79e4b0c5a7
ssdeep: 24576:SL2DSJMVPhknX5+/omk7lN7v3yqtPQI7INCZCc7sxAVT7Z17Gp4AJaMyRH8IDevC:SL+SJMVPhoX8/xk51yq9QqXscp17NAE/
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1517533022A0636B6F5A315314DC4EC3CEB35EC8316265F7FA0D83EC3B45A8563A7D666
sha3_384: bb259db2c58697d913604ca61f07519d20d833a3d0b8080c4d714ada8c74ed63bd7ae83cb3482f9f5794133b24550084
ep_bytes: 60c604244be890fbfffff6d08d642448
timestamp: 2012-05-25 09:26:27

Version Info:

0: [No Data]

Malware.AI.2976085798 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.21470961
FireEyeGeneric.mg.3023594dc5c5220b
McAfeeArtemis!3023594DC5C5
CylanceUnsafe
VIPRETrojan.Generic.21470961
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaPacked:Win32/VMProtect.0e9f82d2
K7GWTrojan ( 7000001c1 )
K7AntiVirusTrojan ( 7000001c1 )
CyrenW32/Trojan.QRWZ-6561
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.ABO
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderTrojan.Generic.21470961
AvastWin32:Malware-gen
TencentWin32.Trojan.Black.Ctgl
Ad-AwareTrojan.Generic.21470961
SophosMal/Generic-R + Mal/VMProtBad-A
F-SecureTrojan.TR/Black.Gen2
ZillyaTrojan.Packed.Win32.112166
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
Trapminemalicious.high.ml.score
EmsisoftTrojan.Generic.21470961 (B)
IkarusTrojan.Win32.VMProtect
GDataTrojan.Generic.21470961
AviraTR/Black.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.397A
ArcabitTrojan.Generic.D1479EF1
MicrosoftTrojan:Win32/Occamy.C
GoogleDetected
AhnLab-V3Unwanted/Win32.Tool.C1956435
ALYacTrojan.Generic.21470961
MAXmalware (ai score=80)
VBA32Trojan.Eb
MalwarebytesMalware.AI.2976085798
RisingTrojan.Generic@AI.93 (RDMK:UlMp06KjWuN3m7yLluZRWg)
YandexTrojan.VMProtect!/To0uSi5Ir4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.11178215.susgen
FortinetW32/VMProtBad.A!tr
BitDefenderThetaGen:NN.ZexaF.34646.FDZ@aStU8Xk
AVGWin32:Malware-gen
Cybereasonmalicious.dc5c52
PandaTrj/GdSda.A

How to remove Malware.AI.2976085798?

Malware.AI.2976085798 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment