Malware

Malware.AI.3118958447 (file analysis)

Malware Removal

The Malware.AI.3118958447 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3118958447 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.3118958447?


File Info:

name: C969DE9FE80FB5461C5B.mlw
path: /opt/CAPEv2/storage/binaries/0d0749644e1a45df19e37746ed3c218ccfbea241ad83378b8481524148509163
crc32: FA077FFD
md5: c969de9fe80fb5461c5bc1abd67345c7
sha1: e8e1445b215a73ac12e46820462f0938247cbdb4
sha256: 0d0749644e1a45df19e37746ed3c218ccfbea241ad83378b8481524148509163
sha512: 5431d0999acc1e7d1ef6920b53e5a03ae4f56119477aa727eb6c46c3897542e13101cd2a250f3791ae3863072fbcdf3b4a62417586bce804c7bebcc4ad301b7d
ssdeep: 384:9s86peno3SdPbWatJLf45a6/k0/BD8TToKIWje:9s9penRa4vf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14EC2F92312DE7EE6C57816307B7353C5C3ADEE055823DA2E69C07529CABE2437A423D9
sha3_384: 17e74845f4e7c7c58389e58ca8f369f598b86e7335db96d511c8be60dc2676b77dd7346caf3550679166a85f0b187997
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-07-27 22:22:14

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: WindowsApplication1
FileVersion: 1.0.0.0
InternalName: Loader.exe
LegalCopyright: Copyright © Microsoft 2018
OriginalFilename: Loader.exe
ProductName: WindowsApplication1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.3118958447 also known as:

BkavW32.Common.27851182
LionicTrojan.Win32.Blocker.V!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68450878
FireEyeGeneric.mg.c969de9fe80fb546
McAfeeArtemis!C969DE9FE80F
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004d38de1 )
AlibabaRansom:MSIL/Blocker.2db27a23
K7GWTrojan ( 004d38de1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.36350.bq0@auZfzVb
CyrenW32/Johnnie.H.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.MEA
APEXMalicious
KasperskyHEUR:Trojan-Ransom.MSIL.Blocker.gen
BitDefenderTrojan.GenericKD.68450878
TencentMalware.Win32.Gencirc.13eb6bc2
SophosMal/Generic-S
VIPRETrojan.GenericKD.68450878
TrendMicroRansom_Blocker.R03BC0WH423
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.68450878 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.68450878
WebrootW32.Injector.Gen
GoogleDetected
MAXmalware (ai score=84)
Antiy-AVLTrojan/MSIL.Injector
ArcabitTrojan.Generic.D4147A3E
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Blocker.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5464448
ALYacTrojan.GenericKD.68450878
TACHYONRansom/W32.DN-Blocker.27136.C
DeepInstinctMALICIOUS
MalwarebytesMalware.AI.3118958447
PandaTrj/Chgt.AD
TrendMicro-HouseCallRansom_Blocker.R03BC0WH423
RisingRansom.Blocker!8.12A (CLOUD)
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.73689294.susgen
FortinetMSIL/Injector.MEA!tr
AVGWin32:InjectorX-gen [Trj]
AvastWin32:InjectorX-gen [Trj]

How to remove Malware.AI.3118958447?

Malware.AI.3118958447 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment