Malware

Malware.AI.3459998102 (file analysis)

Malware Removal

The Malware.AI.3459998102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3459998102 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Detects VirtualBox through the presence of a window
  • Detects VirtualBox using WNetGetProviderName trick
  • Detects Sandboxie through the presence of a library
  • Detects the presence of Wine emulator via function name
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a file
  • Detects VirtualBox through the presence of a registry key
  • Detects VMware through the presence of a device
  • Detects VMware through the presence of a file
  • Detects VMware through the presence of a registry key
  • Collects information to fingerprint the system

How to determine Malware.AI.3459998102?


File Info:

name: 0D67C24D3D78C6159D44.mlw
path: /opt/CAPEv2/storage/binaries/255704027c6af5c8bbc9c4f4c612ffe48c6dbadc8477f1ad7b85693e3d07a702
crc32: FBFD5D39
md5: 0d67c24d3d78c6159d44d24a3342cb94
sha1: caf709c1068c8ee34780e7319a5965ae9a4e09e3
sha256: 255704027c6af5c8bbc9c4f4c612ffe48c6dbadc8477f1ad7b85693e3d07a702
sha512: 19e62b7f13eab11b007a5d63fa6c0f3e0fc0232160040883c094ad57cb362a8112479717f06d6df917caba568a0b4500f482ac098d755cd3fef6041792c8acec
ssdeep: 24576:B+KpPM1cQFUHGOPgyWYkBBdcb22mZ9FpSDSEf1kESn0zgdlXaPWTU5wXedTyP:RRK8zkBBmb2tVEfDSTlXaPWTfXedTU
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12165AE03FB8396B2F892117851B7973A5F3B99205328D9D3CBA02D758D212D16B3E3D9
sha3_384: 5602c674c4de6caa0a037a576babcb71710267932cbe66fc517771eeb62460dd58bcf4dd88b61341823a581b8bb906fb
ep_bytes: e8db050000e974feffff8b4df464890d
timestamp: 2022-07-03 14:46:16

Version Info:

0: [No Data]

Malware.AI.3459998102 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Mint.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.42
FireEyeGen:Heur.Mint.Zard.42
ALYacGen:Heur.Mint.Zard.42
VIPREGen:Heur.Mint.Zard.42
AlibabaTrojan:Win32/Khalesi.8b528b38
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Khalesi.gen
BitDefenderGen:Heur.Mint.Zard.42
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Heur.Mint.Zard.42
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftGen:Heur.Mint.Zard.42 (B)
GDataGen:Heur.Mint.Zard.42
Antiy-AVLTrojan/Generic.ASMalwS.720E
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Dropper/Win.Generic.C5194272
McAfeeArtemis!0D67C24D3D78
MAXmalware (ai score=84)
MalwarebytesMalware.AI.3459998102
TrendMicro-HouseCallTROJ_GEN.R002H09G322
RisingTrojan.Khalesi!8.F103 (CLOUD)
IkarusGen.Mint.Zard
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34786.xvW@aWLzwtki
AVGWin32:DropperX-gen [Drp]

How to remove Malware.AI.3459998102?

Malware.AI.3459998102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment