Malware

Malware.AI.2981653720 removal instruction

Malware Removal

The Malware.AI.2981653720 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2981653720 virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.2981653720?


File Info:

name: 74BF253201D83AEA37D9.mlw
path: /opt/CAPEv2/storage/binaries/4923db38808e4edabe9bc3ae7b344c988966c16f0ab9fecd29cfbfeabb13febf
crc32: DDBFA688
md5: 74bf253201d83aea37d990115f1b0761
sha1: b59a7ef3238a27bfde3be037718000d99a4dec7f
sha256: 4923db38808e4edabe9bc3ae7b344c988966c16f0ab9fecd29cfbfeabb13febf
sha512: 7385dc73f3888321aa4332e424755a5f579d5ec879783178993ebbaae13cf265c889ac27ee88f50de6df37d183d4c9c10f7e37029552ec2817b1ca6cc8f52a1d
ssdeep: 98304:aELyf0jfAX9QqFl0D+BGSo32F06q53P5DeMp8030d5AVZxslYHNSJ00f:aELyM8X/0DIGSo32F06q53P5DeMp803K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184269E21F382C132D49101F2666EAB9F54297E7803A888E3E3C83E5E25B55D35B37B57
sha3_384: c7b90b378b214f793acb659c2674a82851d98937ed80bf3e90bf5fad9a13fa28fa17daa2e7e168aa4dc24f8c24a17f17
ep_bytes: e8539d0100e9000000006a146808526c
timestamp: 2018-09-26 04:48:38

Version Info:

CompanyName: 阿里巴巴(中国)有限公司
FileDescription: 阿里巴巴反钓鱼安全服务
FileVersion: 2.4.0.8
InternalName: TaobaoProtect
LegalCopyright: Copyright (C) 2011-2014 阿里巴巴(中国)有限公司版权所有。
OriginalFilename: TaobaoProtect.exe
ProductName: Miser
ProductVersion: 2.4.0.8
Translation: 0x0804 0x04b0

Malware.AI.2981653720 also known as:

LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.66114721
FireEyeGeneric.mg.74bf253201d83aea
ALYacTrojan.GenericKD.66114721
MalwarebytesMalware.AI.2981653720
ZillyaTrojan.PolyPatch.Win32.8
SangforTrojan.Win32.Agent.Va2i
Cybereasonmalicious.3238a2
BitDefenderThetaGen:NN.ZexaF.36164.@Z3@aif1C9aj
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.66114721
SophosGeneric ML PUA (PUA)
VIPRETrojan.GenericKD.66114721
McAfee-GW-EditionBehavesLike.Win32.Generic.rm
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.66114721 (B)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Generic
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Generic.D3F0D4A1
GDataTrojan.GenericKD.66114721
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09CS23
FortinetPossibleThreat.PALLASNET.H
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.2981653720?

Malware.AI.2981653720 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment