Malware

Should I remove “Malware.AI.340483283”?

Malware Removal

The Malware.AI.340483283 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.340483283 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Malware.AI.340483283?


File Info:

name: EC795F0D7BBED9026536.mlw
path: /opt/CAPEv2/storage/binaries/e126ff7d01fa15910d0483f006570b71523de799d17b3d3fe841a631f62bb611
crc32: E1787F24
md5: ec795f0d7bbed9026536c6e5f35d6cb0
sha1: b56e7cbc927e4f7f9d2eb5332aa9faa7edb0bc1c
sha256: e126ff7d01fa15910d0483f006570b71523de799d17b3d3fe841a631f62bb611
sha512: c4509d9ad186d78c16af65ce2f7570b7ee11e8a7920a1f1b70255d8ed2c25ef5c689c56ffe02d12ae8ef1929097f8ebeb43671e78587f5288a91a5f80ee826e8
ssdeep: 3072:ZYAfxX3lz4WR6IM4lGTMEe4ZhOG8JlTv0rplN:ZYgh1MbEkOGkzyp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13484CF49B353C972C069013454CF8791AE35BE901D938BCA77C1BE2FAD36360E92726D
sha3_384: c94796d43493fac306f12bf9ad4317c83581260ca105d68ed6345859bc6f22d26ea8b177357e97ff0dee448294321556
ep_bytes: 558bec81c4e8feffff6a40eb03ff0c24
timestamp: 2002-02-24 19:10:21

Version Info:

0: [No Data]

Malware.AI.340483283 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.28287
CynetMalicious (score: 100)
FireEyeGeneric.mg.ec795f0d7bbed902
CAT-QuickHealTrojan.Quolko.A
ALYacGen:Heur.VIZ.!e!.1
CylanceUnsafe
ZillyaBackdoor.Shiz.Win32.4464
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Ramnit.36aa9c57
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderThetaGen:NN.ZexaF.34212.xmW@ayudEtfc
VirITWin32.Scribble.AC
CyrenW32/Bamital.I
SymantecTrojan.Bamital
ESET-NOD32Win32/Virut.NBP
TrendMicro-HouseCallTROJ_BAMITAL.SML
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-7584013-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.VIZ.!e!.1
NANO-AntivirusTrojan.Win32.Kryptik.bstyem
MicroWorld-eScanGen:Heur.VIZ.!e!.1
AvastWin32:Vitro [Inf]
RisingVirus.Virut!8.44 (CLOUD)
Ad-AwareGen:Heur.VIZ.!e!.1
EmsisoftGen:Heur.VIZ.!e!.1 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
BaiduWin32.Virus.Virut.gen
VIPRETrojan.Win32.Agent.ie (v)
TrendMicroTROJ_BAMITAL.SML
McAfee-GW-EditionBehavesLike.Win32.Swisyn.fz
SophosMal/Generic-R + Mal/Zbot-AV
IkarusTrojan-Ransom.PornoBlocker
GDataGen:Heur.VIZ.!e!.1
JiangminTrojanDownloader.Piker.bhv
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.AutoRun
KingsoftHeur.SSC.2698478.1216.(kcloud)
ArcabitTrojan.VIZ.!e!.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Ramnit.A
SentinelOneStatic AI – Malicious PE
AhnLab-V3Trojan/Win32.FraudPack.R3415
Acronissuspicious
McAfeePWS-Zbot.gen.uz
VBA32Trojan.MTA.01056
MalwarebytesMalware.AI.340483283
APEXMalicious
TencentMalware.Win32.Gencirc.10b88c95
MAXmalware (ai score=100)
eGambitGeneric.Downloader
FortinetW32/Qbot.AEM!tr
AVGWin32:Vitro [Inf]
Cybereasonmalicious.d7bbed
PandaW32/Sality.AO

How to remove Malware.AI.340483283?

Malware.AI.340483283 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment