Malware

Malware.AI.3502545628 (file analysis)

Malware Removal

The Malware.AI.3502545628 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3502545628 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Malware.AI.3502545628?


File Info:

name: EC2478CF9F5D9769D3A1.mlw
path: /opt/CAPEv2/storage/binaries/490f6fb07f02919377cde73891605f081e78a778eb0fb272b3c0e1f01d3cab48
crc32: 8005F4E5
md5: ec2478cf9f5d9769d3a1716933d54ef7
sha1: 29e8fd3619dadbd3ce6128395912e4547dfa2e06
sha256: 490f6fb07f02919377cde73891605f081e78a778eb0fb272b3c0e1f01d3cab48
sha512: e44599904831009dcc7101993e443ffb1624a374eb7f01eb9198bb7733eca86d87cc6e205f7bc7bd0fff20448ae110c5a78fad9c0ea13a533d7a766a71ab6d94
ssdeep: 49152:MQinshNXlom8QluUXAARXNB6tiyt6jd1HWS5:Mtn8EmJuuAADgtiy8HHf5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E375231EB2DCA679F051C0752E2144A45365FC302839CA0FFB86EF297AF59C79826B47
sha3_384: 8f2076f2903e1826efd387d7586f8108dd3459e2e3aa406c1fdb929223679480fe0a41a01fc9b9380585e9b159472953
ep_bytes: 680c1f4000e8f0ffffff000000000000
timestamp: 2022-03-21 22:37:21

Version Info:

CompanyName: Orlando's VBA and Excel Site
FileDescription: Excel application converted by XLtoEXE utility.
LegalCopyright: Copyright © 2003-2022 Francisco Orlando Magalhães Filho. All rights reserved.
LegalTrademarks: Microsoft® Excel® is a registered trademark of Microsoft Corporation.
ProductName: XLtoEXE
FileVersion: 2.00.0006
ProductVersion: 2.00.0006
InternalName: XLtoEXE
OriginalFilename: XLtoEXE.exe
Translation: 0x0409 0x04b0

Malware.AI.3502545628 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (moderate confidence)
ClamAVWin.Malware.Unsafe-6830628-0
CAT-QuickHealTrojan.AgentVMF.S9456294
CylanceUnsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.619dad
CyrenW32/Razy.HL.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyVHO:Trojan.Win32.Convagent.gen
EmsisoftApplication.Generic (A)
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.ec2478cf9f5d9769
SophosGeneric ML PUA (PUA)
Antiy-AVLTrojan/Generic.ASMalwS.6C82
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
VBA32Trojan.VBKrypt
MalwarebytesMalware.AI.3502545628
RisingMalware.FakeXLS/ICON!1.6AC3 (CLASSIC)
FortinetW32/Razy.597649!tr

How to remove Malware.AI.3502545628?

Malware.AI.3502545628 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment