Malware

About “Malware.AI.2999385435” infection

Malware Removal

The Malware.AI.2999385435 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2999385435 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.2999385435?


File Info:

name: BC384EEFAF5EDEFFBEA5.mlw
path: /opt/CAPEv2/storage/binaries/0890744fa1fc7f7a51b6e8fe10c3bebcf81723b7124375b8440864b353c68871
crc32: A37349A3
md5: bc384eefaf5edeffbea5253dd48993b6
sha1: fcad85f34f917233a038768c5b4363a43b1c38f4
sha256: 0890744fa1fc7f7a51b6e8fe10c3bebcf81723b7124375b8440864b353c68871
sha512: ff28bc220d669384366db30c67b51e7cdb34623da0503f2fd71de8cd3ddcac453ddac01d615438bbde3ab0273205ed9a4b56ed35587df4fcdbd4a7b501a6b0aa
ssdeep: 3072:ScLK1Czi8Rmx0O9RBgkR/X+0HfI/Fh27qudk5D:S0iJx0O9DlpXe32hc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17FC302A520853030DAF8737247628C216F9B797937398BADF78E590C3FF8361C698652
sha3_384: f07c05f9dbf229033b0a38a94dd73c1edf52241befc7a8b46a73afe3c4a72f07ecdb54a4e80526725bd580f1178bdea7
ep_bytes: 6a00ff15b0304000a3301140006a0068
timestamp: 2016-05-23 19:25:59

Version Info:

0: [No Data]

Malware.AI.2999385435 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.248643
SkyhighBehavesLike.Win32.Backdoor.cc
McAfeeGenericRXEM-PH!BC384EEFAF5E
MalwarebytesMalware.AI.2999385435
VIPREGen:Variant.Ulise.248643
BitDefenderGen:Variant.Ulise.248643
BitDefenderThetaGen:NN.ZexaF.36792.hqW@a8eXGtoi
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
CynetMalicious (score: 100)
APEXMalicious
RisingTrojan.Generic@AI.99 (RDML:24Vgxutf4n4BlCaGLbrGbw)
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Crypt.XPACK.Gen
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bc384eefaf5edeff
EmsisoftGen:Variant.Ulise.248643 (B)
VaristW32/Razy.IK.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLGrayWare/Win32.Generic
ArcabitTrojan.Ulise.D3CB43
GDataGen:Variant.Ulise.248643
GoogleDetected
VBA32Trojan.Script.Phonzy
ALYacGen:Variant.Ulise.248643
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/GdSda.A
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Sality [Inf]
Cybereasonmalicious.34f917
AvastWin32:Sality [Inf]

How to remove Malware.AI.2999385435?

Malware.AI.2999385435 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment