Malware

Should I remove “Malware.AI.308769074”?

Malware Removal

The Malware.AI.308769074 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.308769074 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.308769074?


File Info:

name: 99862F027E4ABB892D49.mlw
path: /opt/CAPEv2/storage/binaries/fc7989603d34bb5eb60efdd12100cb0ceac964e0f10087b332ce91318f00ac5f
crc32: 12A7BBC7
md5: 99862f027e4abb892d497ee60b0ec93b
sha1: cf8e336e7c80c1654ea26001c4f0267c7b397af8
sha256: fc7989603d34bb5eb60efdd12100cb0ceac964e0f10087b332ce91318f00ac5f
sha512: 4ca4f7a641ff0379403a599a209d99e2f2e16d07927c428b7d9c28bec21dbd26d2a0def87b1f15971d47e04f04f75ccf3278df84c89d7846aa9e9d89c7c32619
ssdeep: 12288:ABBmppvi9VW8+fyEEkIkojxFb1lyUiB0JDBVrXCe0L5DuCOfChcKC3btwpn04vx:afW85EEk5ojxFb1ly8JDBYDEICrte045
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155C42383CBF95625F60105B41C068E9E1905FEBE8E9B1F5E2E6C3D5F0BB6640782EC61
sha3_384: fa66099fa8a7076dd6d3ab4f993e144c16f8a26afc44ba3bb831cc7be73cccc204ea7cb5b2ddf846060fa577ef0509e6
ep_bytes: 60be008053008dbe0090ecffc787c860
timestamp: 2023-07-18 22:31:48

Version Info:

FileVersion: 13.2.0.0
FileDescription: 易语言程序
ProductName: 微伴侣
ProductVersion: 13.2.0.0
CompanyName: wxcos
LegalCopyright: wxcos 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Malware.AI.308769074 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Tedy.4!c
MicroWorld-eScanGen:Variant.Tedy.411968
ClamAVWin.Malware.Trojanx-9951053-0
FireEyeGen:Variant.Tedy.411968
CAT-QuickHealTrojan.IGENERIC
ALYacGen:Variant.Tedy.411968
Cylanceunsafe
SangforTrojan.Win32.Agent.Vvpz
K7AntiVirusTrojan ( 005a99bf1 )
K7GWTrojan ( 005a99bf1 )
CyrenW32/ABRisk.ANBW-9212
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Agent.AFRG
APEXMalicious
CynetMalicious (score: 99)
BitDefenderGen:Variant.Tedy.411968
AvastWin32:Evo-gen [Trj]
F-SecureTrojan.TR/Agent.bfxmd
VIPREGen:Variant.Tedy.411968
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Tedy.411968 (B)
IkarusTrojan.Agent4
GDataGen:Variant.Tedy.411968
AviraTR/Agent.bfxmd
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Tedy.D64940
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeArtemis!99862F027E4A
MAXmalware (ai score=81)
MalwarebytesMalware.AI.308769074
TrendMicro-HouseCallTROJ_GEN.R011H09HN23
RisingTrojan.Agent!8.B1E (CLOUD)
MaxSecureDropper.Dinwod.frindll
FortinetW32/Agent.AFRG!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Malware.AI.308769074?

Malware.AI.308769074 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment