Malware

Malware.AI.300211912 malicious file

Malware Removal

The Malware.AI.300211912 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.300211912 virus can do?

  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid

How to determine Malware.AI.300211912?


File Info:

name: D09BCB1365C0BD5F2207.mlw
path: /opt/CAPEv2/storage/binaries/212acbf49c0aa6c0a17a2e976c76c34cc5d604217ef2e7f3b85de15b694ba5fd
crc32: F249F50A
md5: d09bcb1365c0bd5f2207c34b7d837e21
sha1: e3683e31d1d08dd5fd6cb0bc8ce32a5c2bda8858
sha256: 212acbf49c0aa6c0a17a2e976c76c34cc5d604217ef2e7f3b85de15b694ba5fd
sha512: 85ee99836eafea76026be9cdbb37bb40b684b705bce60d1d329cc1d947cdddfdfa4d7040a677031386a3e646163eddc3c7bba2a31a13561fa812f2ba2a525ca3
ssdeep: 12288:NS1zkkNtheQk/azdUPUHoYSq8J5IEseUOuuG:sGQvd9mjnU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5F45C3D77C1B916D43E153140F99A9263B1B68B2B52CB1F6ACA079C6F021CF3B4719A
sha3_384: eab57809cc65aaf171dc428d65313fb93d2616bb81d935ae281f7158f714f79d4abbd4a13cf30086afc16afb9be4048d
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-05-14 00:24:16

Version Info:

Translation: 0x0000 0x04b0
Comments: s(7X%9Ji5w/A+6
CompanyName: 3Zb#r6&M)aW58*
FileDescription: q+9G/3EmaX)52^j
FileVersion: 1.1.1.1
InternalName: hhh.exe
LegalCopyright: Copyright © 2014 - 2019
OriginalFilename: hhh.exe
ProductName: q+9G/3EmaX)52^j
ProductVersion: 1.1.1.1
Assembly Version: 0.0.0.0

Malware.AI.300211912 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Multi.Generic.4!c
MicroWorld-eScanTrojan.MSIL.Basic.8.Gen
FireEyeGeneric.mg.d09bcb1365c0bd5f
SkyhighBehavesLike.Win32.Generic.bm
ALYacTrojan.MSIL.Basic.8.Gen
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0056c6e41 )
AlibabaBackdoor:MSIL/AgentTesla.36eccdd7
K7GWTrojan ( 0056c6e41 )
Cybereasonmalicious.1d1d08
BitDefenderThetaGen:NN.ZemsilF.36744.Vm0@aysxDQc
SymantecTrojan.Gen.2
ElasticWindows.Trojan.AgentTesla
ESET-NOD32a variant of MSIL/Kryptik.XIJ
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.Androm.gen
BitDefenderTrojan.MSIL.Basic.8.Gen
NANO-AntivirusTrojan.Win32.Androm.hrxelz
AvastWin32:PWSX-gen [Trj]
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1306853
VIPRETrojan.MSIL.Basic.8.Gen
EmsisoftTrojan.MSIL.Basic.8.Gen (B)
SentinelOneStatic AI – Malicious PE
WebrootPua.Adware.Gen
VaristW32/MSIL_Kryptik.BLR.gen!Eldorado
AviraHEUR/AGEN.1306853
MAXmalware (ai score=83)
Antiy-AVLTrojan[Backdoor]/MSIL.Androm
Kingsoftmalware.kb.c.1000
MicrosoftTrojan:MSIL/AgentTesla.PAD!MTB
ArcabitTrojan.MSIL.Basic.8.Gen
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
GDataTrojan.MSIL.Basic.8.Gen
GoogleDetected
McAfeePWS-FCQP!D09BCB1365C0
MalwarebytesMalware.AI.300211912
PandaTrj/GdSda.A
TrendMicro-HouseCallPossible_SMNEGASTEAL
TencentMsil.Backdoor.Androm.Dtgl
IkarusTrojan-Spy.AgentTesla
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.XIM!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.300211912?

Malware.AI.300211912 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment