Malware

What is “Malware.AI.3284540609”?

Malware Removal

The Malware.AI.3284540609 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3284540609 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing

How to determine Malware.AI.3284540609?


File Info:

name: 5DE9E561E71F18984960.mlw
path: /opt/CAPEv2/storage/binaries/4c6571f9794238977f58db5e8ba3cc21116c22cb37f83a9847e0e75122fe1ec7
crc32: EC569515
md5: 5de9e561e71f1898496067389592fe4e
sha1: 847298c2207460a65756002eb7a5ddf04c11d4f1
sha256: 4c6571f9794238977f58db5e8ba3cc21116c22cb37f83a9847e0e75122fe1ec7
sha512: abf24f0eb03eca835ac605d4b04aaef8030239574444348afb091da86396dbfe0167ba007b882617e5aed6c80903cb86f9e676352cd0a06acc8f2bdc641b6ec9
ssdeep: 3072:VUJqlEiFPFFy5N/oLlCbkahiASzVL+yikNMca7HAJM:VLFON/bkahCMAJM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194F37B2174C1C873D8B7193158F8DA726E7CF9315F744AEB639807BA5F201C0AA39A67
sha3_384: 381b88664c85826a38f8b22a063a703e462b75cbb330164da0f266e7e7db0a93931aaf4f8aaf0beae18b2aeec0814a94
ep_bytes: e8cd050000e98efeffffff25c0c24100
timestamp: 2019-11-13 05:57:03

Version Info:

FileVersion: 12.1.1
ProductVersion: 12.2.2
Translation: 0x0409 0x04b0

Malware.AI.3284540609 also known as:

LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen2.3027
MicroWorld-eScanTrojan.GenericKD.68257592
FireEyeGeneric.mg.5de9e561e71f1898
McAfeeArtemis!5DE9E561E71F
MalwarebytesMalware.AI.3284540609
ZillyaTrojan.BalkanDoor.Win32.4
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00559c1b1 )
AlibabaTrojan:Win32/BalkanDoor.2ddc28bf
K7GWTrojan ( 00559c1b1 )
Cybereasonmalicious.1e71f1
BitDefenderThetaGen:NN.ZexaCO.36348.jC2@aKDXVuki
VirITTrojan.Win32.Genus.IHW
SymantecML.Attribute.HighConfidence
ZonerTrojan.Win32.85524
CynetMalicious (score: 99)
BitDefenderTrojan.GenericKD.68257592
NANO-AntivirusTrojan.Win32.BalkanDoor.ghtqac
AvastWin32:DangerousSig [Trj]
SophosTroj/Balkan-A
F-SecureTrojan.TR/Redcap.oleyo
VIPRETrojan.GenericKD.68257592
TrendMicroTROJ_GEN.R002C0RGF23
McAfee-GW-EditionArtemis!Trojan
EmsisoftMalCert-S.AP (A)
JiangminTrojan.Agent.cllm
AviraTR/Redcap.oleyo
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Tiggre
XcitiumMalware@#15ypb52ynsppc
ArcabitTrojan.Generic.D4118738
ZoneAlarmTrojan.Win32.Agent.xacloo
GDataTrojan.GenericKD.68257592
GoogleDetected
VBA32Trojan.Agent
ALYacTrojan.GenericKD.68257592
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0RGF23
TencentMalware.Win32.Gencirc.1159a832
YandexTrojan.BalkanDoor!Bvxg0RI4b3Q
IkarusTrojan.Win32.Balkandoor
MaxSecureTrojan.Malware.74696440.susgen
FortinetW32/BalkanDoor.C!tr
AVGWin32:DangerousSig [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.3284540609?

Malware.AI.3284540609 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment