Malware

Malware.AI.3008025514 malicious file

Malware Removal

The Malware.AI.3008025514 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3008025514 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Malware.AI.3008025514?


File Info:

name: 38FDEBFD559DC4733395.mlw
path: /opt/CAPEv2/storage/binaries/f74d7d579d5b96be98ecc14091c63740be76e74c1e9ccdf3550d1fccc86c782e
crc32: 4B287ADD
md5: 38fdebfd559dc47333952ac3213e6c65
sha1: 7661683042e1462aa50379273f6d147c233f38b2
sha256: f74d7d579d5b96be98ecc14091c63740be76e74c1e9ccdf3550d1fccc86c782e
sha512: c5a42e48f0597d06ba2430ebcf304555114d0c3d56b3fedec29f1850f784de63e8b48ccf4f01f4c24b40b120cf8eb083f5e2e4b1694333f866e99be60c363e29
ssdeep: 384:q/CbUFtZSrf72bgRylcJbm/12T2kb1+GD5dzXt:7Q6agXmtMPb1tDr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18E629D617FB08F77EAB4FEBB515270E1037C210D02EEA4A42DE51F2B19C2059CD8A8B0
sha3_384: 2aefb075a14c2bbd8279e2986fd70cf8d614779e7bd4beb660f47c64c305b81913bb940c0e0b9eeac214448639c4f392
ep_bytes: 60be008040008dbe0090ffff57eb0b90
timestamp: 2007-08-28 06:42:32

Version Info:

0: [No Data]

Malware.AI.3008025514 also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanDropped:Trojan.Gunex.A
FireEyeGeneric.mg.38fdebfd559dc473
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeegeneric!bg.eox
MalwarebytesMalware.AI.3008025514
ZillyaTrojan.Agent.Win32.26436
SangforSuspicious.Win32.Save.a
K7AntiVirusRootKit ( 0055e3fe1 )
BitDefenderDropped:Trojan.Gunex.A
K7GWRootKit ( 0055e3fe1 )
Cybereasonmalicious.d559dc
BitDefenderThetaAI:Packer.7A407B951B
CyrenW32/S-0b54b2a8!Eldorado
SymantecDownloader
ESET-NOD32a variant of Win32/Rootkit.Agent.NWA
BaiduWin32.Rootkit.Agent.au
APEXMalicious
ClamAVWin.Trojan.Agent-44707
KasperskyTrojan-Dropper.Win32.Agent.cdp
NANO-AntivirusTrojan.Win32.Agent.dqypyl
AvastWin32:Malware-gen
RisingTrojan.Rootkit!1.AEDA (CLASSIC)
Ad-AwareDropped:Trojan.Gunex.A
SophosML/PE-A + Troj/DownLd-BDS
ComodoTrojWare.Win32.TrojanDownloader.Agent.eing@1qszy4
DrWebTrojan.DownLoader.52965
VIPREDropped:Trojan.Gunex.A
TrendMicroTSPY_LAQMA.SMI
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
Trapminemalicious.moderate.ml.score
EmsisoftDropped:Trojan.Gunex.A (B)
IkarusTrojan.Zlob
JiangminTrojanDownloader.Agent.mcp
AviraTR/Drop.Agent.NEM.2
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASBOL.C578
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataDropped:Trojan.Gunex.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R10220
VBA32BScope.Trojan.Agent
ALYacDropped:Trojan.Gunex.A
CylanceUnsafe
TrendMicro-HouseCallTSPY_LAQMA.SMI
YandexTrojan.GenAsa!h96gzF8YkWE
SentinelOneStatic AI – Malicious PE
FortinetW32/Dloader.BDS!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3008025514?

Malware.AI.3008025514 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment