Malware

About “Malware.AI.3149302635” infection

Malware Removal

The Malware.AI.3149302635 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3149302635 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.3149302635?


File Info:

name: 6687E22DFA0AE47D3011.mlw
path: /opt/CAPEv2/storage/binaries/bd120fbbe3e63335eb7402ffbd961da02cb5531bdea11cfc0709c5bfa9279a24
crc32: F2C19E50
md5: 6687e22dfa0ae47d3011fff494bf9501
sha1: 0ab599041a89e3d3f1147aa15cf3d4b5ef6736ae
sha256: bd120fbbe3e63335eb7402ffbd961da02cb5531bdea11cfc0709c5bfa9279a24
sha512: 64d6a1ebb0556a210a0a9deaada04e8342c04b6c20610ffc7db4dffb0ac71da7d39190b3fc0d11de5ba080ecd4b0ee1f8422e370e6e4975d893335613aa2b0ac
ssdeep: 24576:fClIaY6Di3olvfCPOjV1P4NUzACF826XDXM344Zz5tB98rHEkLAzFSejmagu:0Di4lvfCPOjVqNUzAYzpIHBLCSpu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175F5E0036BFD0948F5F32B79967A88509A37BC560A39E59E005C1D4D0F73A819DB2FB2
sha3_384: 7b5bdb1abeb63b0e60225129422976d83da60502900c11187fb3d83be6fc52ae5c318767bc402e2c57f886f786e6714d
ep_bytes: 5589e583ed18c745ecaf3840006064a1
timestamp: 2020-11-04 10:49:43

Version Info:

CompanyName: CyberLink Corp.
Translation: 0x0000 0x04b0

Malware.AI.3149302635 also known as:

BkavW32.AIDetect.malware2
LionicVirus.Win32.Parite.lDG5
MicroWorld-eScanGen:Variant.Babar.22371
FireEyeGeneric.mg.6687e22dfa0ae47d
ALYacGen:Variant.Babar.22371
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
AlibabaTrojan:Win32/Generic.21270c7c
Cybereasonmalicious.dfa0ae
ArcabitTrojan.Babar.D5763
CyrenW32/Agent.RNIZ-9325
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002H0CB622
Paloaltogeneric.ml
BitDefenderGen:Variant.Babar.22371
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Babar.22371
SophosGeneric PUA AK (PUA)
McAfee-GW-EditionBehavesLike.Win32.BadFile.wm
EmsisoftGen:Variant.Babar.22371 (B)
IkarusTrojan.Patched
AviraTR/Patched.Gen
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Babar.22371
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!6687E22DFA0A
MAXmalware (ai score=84)
MalwarebytesMalware.AI.3149302635
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
MaxSecureTrojan.Malware.109090318.susgen
FortinetW32/Kryptik.EOCT!tr
AVGWin32:Malware-gen

How to remove Malware.AI.3149302635?

Malware.AI.3149302635 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment