Malware

Malware.AI.36003398 removal instruction

Malware Removal

The Malware.AI.36003398 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.36003398 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Network activity detected but not expressed in API logs
  • Harvests cookies for information gathering

How to determine Malware.AI.36003398?


File Info:

name: 0D2D2274216E2715F313.mlw
path: /opt/CAPEv2/storage/binaries/2a92cb131f61afa7955ef4b38c5fb541f26f87f2f5caada995137b907c92370a
crc32: F0655E9F
md5: 0d2d2274216e2715f313605e4cd392a6
sha1: 51d9820ddffaec98b7c188aeb26e5f324052309b
sha256: 2a92cb131f61afa7955ef4b38c5fb541f26f87f2f5caada995137b907c92370a
sha512: 4584590468b5796eb93cd1d932739238bc228ff5f48307a3c8f8fc73e52c461f2c217ded35ca482cb18d1f0935bdb17193475d652e6ba21104c3fd157f666078
ssdeep: 24576:10ZkwOi8kWudwXbAVgGkExb4Cxj8atNUJpxJCsW:CdOi8QuXhG3Uat2JCsW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C358D22FA82D0B1E9D100B252FE6BF74C387226433998DBB6D41D695E701E2373E656
sha3_384: 20fd58a454504ae92b6724b8c27ca1209a8c9f50cb8aabeb4d285a81915f76e2042c6f493ba0caea8440e793fc203ab0
ep_bytes: e865050000e987feffffff25c8324c00
timestamp: 2021-05-14 03:45:47

Version Info:

0: [No Data]

Malware.AI.36003398 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.JP.dvX@aOwA8ini
FireEyeGeneric.mg.0d2d2274216e2715
CAT-QuickHealTrojan.GenericRI.S21049230
McAfeeGenericRXPH-OP!0D2D2274216E
CylanceUnsafe
ZillyaTrojan.Sdum.Win32.4434
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 0057e4811 )
K7GWAdware ( 0057e4811 )
Cybereasonmalicious.4216e2
BitDefenderThetaAI:Packer.86FE2FAF1F
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.AV potentially unwanted
APEXMalicious
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Trojan.Heur.JP.dvX@aOwA8ini
NANO-AntivirusTrojan.Win32.Generic.iwcowg
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Trojan.Heur.JP.dvX@aOwA8ini
SophosML/PE-A
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R03BC0PGQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftGen:Trojan.Heur.JP.dvX@aOwA8ini (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Trojan.Heur.JP.dvX@aOwA8ini
JiangminTrojan.Multi.aum
Antiy-AVLTrojan/Win32.Generic
ArcabitTrojan.Heur.JP.EAD1B62
MicrosoftTrojan:Win32/Wacatac.A!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R427926
Acronissuspicious
VBA32BScope.Trojan.Sdum
ALYacGen:Trojan.Heur.JP.dvX@aOwA8ini
MAXmalware (ai score=85)
MalwarebytesMalware.AI.36003398
TrendMicro-HouseCallTROJ_GEN.R03BC0PGQ21
RisingStealer.Cookie!1.D778 (CLASSIC)
YandexRiskware.Agent!vY/JXclAaZo
IkarusPUA.Agent
MaxSecureTrojan.Malware.82199810.susgen
FortinetRiskware/Agent
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Malware.AI.36003398?

Malware.AI.36003398 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment