Malware

Malware.AI.354089328 malicious file

Malware Removal

The Malware.AI.354089328 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.354089328 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid

How to determine Malware.AI.354089328?


File Info:

name: 97CD1DB9AEAA7CB13D79.mlw
path: /opt/CAPEv2/storage/binaries/182c3e510ee953586cfc5e95bd87cac29a468ead0cb09d7ffe2a676e59e610d6
crc32: DCC93DD5
md5: 97cd1db9aeaa7cb13d79626d31117279
sha1: dfea121c4d8f44d8fc59300741d9c3eeb61e9fc9
sha256: 182c3e510ee953586cfc5e95bd87cac29a468ead0cb09d7ffe2a676e59e610d6
sha512: 60173d5cdcc9339db5a43f166ff4905558c5a6b317d03fcfef010203e561d89a73bbff930cdc2739607833977b70edd2b228ac1b52c9f9107e376ecd7fbe6c8e
ssdeep: 24576:bEgO5T5oJMd8SK8frX4WwYqBqzuztrKAjWoShf3oU6MVBloMvuILo8AePpGI1u:AKSGSK8frJw7fhKAjpSd4MrlozI88AYK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE4523122858D867E4D701B00AB5CA42DE3EF8B61136E619A2D07D8B6E767D6DC3F307
sha3_384: 519429b9d1028e8c642597899f2e3d31b804293654becbee6f7124e2c4b29abe13262bf7f829e8a884a101fa53998882
ep_bytes: 6a606898614000e803040000bf940000
timestamp: 2007-06-11 05:52:51

Version Info:

0: [No Data]

Malware.AI.354089328 also known as:

LionicTrojan.Win32.Agent.b!c
MicroWorld-eScanGen:Trojan.Heur.irZ@HzFlPgbj
FireEyeGen:Trojan.Heur.irZ@HzFlPgbj
McAfeeArtemis!97CD1DB9AEAA
CylanceUnsafe
ZillyaAdware.Ejik.Win32.948
K7AntiVirusAdware ( 0056dec91 )
AlibabaAdWare:Win32/Brontok.9df33ea8
K7GWAdware ( 0056dec91 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Adware.Ejik.CW
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Agent.exm
BitDefenderGen:Trojan.Heur.irZ@HzFlPgbj
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Trojan.Heur.irZ@HzFlPgbj
SophosGeneric PUA NP (PUA)
ComodoApplication.Win32.Adware.Ejik.CW@bzb7
DrWebTrojan.Click2.44941
McAfee-GW-EditionBehavesLike.Win32.PUP.tc
EmsisoftGen:Trojan.Heur.irZ@HzFlPgbj (B)
JiangminTrojan.Generic.haxok
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
KingsoftHeur.SSC.2723193.1216.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Trojan.Heur.irZ@HzFlPgbj
CynetMalicious (score: 99)
BitDefenderThetaAI:Packer.C382C5B51C
ALYacGen:Trojan.Heur.irZ@HzFlPgbj
MalwarebytesMalware.AI.354089328
TrendMicro-HouseCallTROJ_GEN.R002H0CKR21
TencentWin32.Trojan.Generic.Hvtd
YandexAdware.Ejik!A1CyklEpQ+4
IkarusRootkit.Win32.Agent
FortinetRiskware/Ejik
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.9aeaa7
PandaTrj/CI.A

How to remove Malware.AI.354089328?

Malware.AI.354089328 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment