Malware

What is “Malware.AI.3023689498”?

Malware Removal

The Malware.AI.3023689498 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3023689498 virus can do?

  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.3023689498?


File Info:

name: DCEB5388EDDADAFB18CD.mlw
path: /opt/CAPEv2/storage/binaries/f34d39b6edc8fe22483a3af27a76b918ad6952a167344f96359b6a3353759b20
crc32: B97D12AE
md5: dceb5388eddadafb18cdeca69c2201d6
sha1: b236d14809d0802c27facc52e707f6f3ff19eb05
sha256: f34d39b6edc8fe22483a3af27a76b918ad6952a167344f96359b6a3353759b20
sha512: bd5338bba5f81c3feb41721e34cbdf3a25248084a782734feb4032a73b5217c22f3046f64f4221a1b2d51f8079650e4349157f1ae15b8f23a9cd5e5757cb14f3
ssdeep: 192:TLbT1YlxCtT81a0LZ1Fuz7IDjTJfqA0ofXbjOMo5auWHLV7E53z6gJoZgT29IAQV:TLbar3xjTVqA0EXbjE5a1R7dOT29jQV
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15952F843FA644F72CFD481B4343EEA4286FBB265AFD15A93ABE468590C601D19C1B06F
sha3_384: 7b55479e8ec545193195c8d4281730cf49d842406380770beca9ab4fcf99020b4e6625037dc37105786898cf83d1c313
ep_bytes: e801040000e974feffff558bec6a00ff
timestamp: 2021-07-27 03:51:24

Version Info:

0: [No Data]

Malware.AI.3023689498 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.i!c
MicroWorld-eScanGen:Variant.Zusy.412568
ClamAVWin.Malware.Zusy-9891909-0
McAfeeGenericRXPE-LX!DCEB5388EDDA
MalwarebytesMalware.AI.3023689498
VIPREGen:Variant.Zusy.412568
SangforTrojan.Win32.Stealer.gen
K7AntiVirusTrojan-Downloader ( 0057ff911 )
AlibabaTrojanPSW:Win32/Stealer.2110c9dc
K7GWTrojan-Downloader ( 0057ff911 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FTE
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.Stealer.gen
BitDefenderGen:Variant.Zusy.412568
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.115c8a87
EmsisoftGen:Variant.Zusy.412568 (B)
F-SecureHeuristic.HEUR/AGEN.1315741
ZillyaTrojan.Stealer.Win32.12093
TrendMicroMal_DLDER
McAfee-GW-EditionBehavesLike.Win32.Generic.lm
FireEyeGeneric.mg.dceb5388eddadafb
SophosMal/Generic-S
IkarusTrojan.SelfDel
GDataGen:Variant.Zusy.412568
JiangminTrojan.Generic.gyrwo
AviraHEUR/AGEN.1315741
Antiy-AVLTrojan[PSW]/Win32.Stealer
ArcabitTrojan.Zusy.D64B98
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealer.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Dlder.R425274
Acronissuspicious
ALYacGen:Variant.Zusy.412568
MAXmalware (ai score=85)
VBA32BScope.Trojan.NanoBot
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_DLDER
RisingTrojan.Generic@AI.100 (RDML:QkdjSqui4NN++uWdiDHZsw)
MaxSecureTrojan.Malware.73788987.susgen
FortinetW32/Agent.FTE!tr.dldr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3023689498?

Malware.AI.3023689498 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment