Malware

Malware.AI.393240895 (file analysis)

Malware Removal

The Malware.AI.393240895 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.393240895 virus can do?

  • Unconventionial language used in binary resources: Hungarian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.393240895?


File Info:

name: FC0D34CD32FBADAC0360.mlw
path: /opt/CAPEv2/storage/binaries/fa13f569c5b6bc1028142c046b4523318640914c2d70cfdeb1225efc64f8b50e
crc32: DBDFC0CA
md5: fc0d34cd32fbadac036042dedd9f389f
sha1: 53019f2432a7e69af6c04333edcc900396d625b1
sha256: fa13f569c5b6bc1028142c046b4523318640914c2d70cfdeb1225efc64f8b50e
sha512: 46c5043f2b9dcab4f5387eab8289e2f561f3634f1d9d885ed00755f85283976cf819f09a20958f0f5291f064280c5dbdc91af2fff00523e09ad54d90414a757a
ssdeep: 24576:2rxyf/XVkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkwkf:4xyfvo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199B64AC077E294B9E2E27A7089755F90963BBC12EB3056DB3237370E1B756D09931B22
sha3_384: c6047c0bf1594835741ad99de94932defa08d669bc037b762bd145a21f56cc5eac1322fac6b84de38be4f382cc3c498f
ep_bytes: e885310000e979feffff8bff558bec8b
timestamp: 2021-05-02 06:11:08

Version Info:

InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkort
ProjectVersion: 3.14.72.77
Translation: 0x0129 0x07bc

Malware.AI.393240895 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.49985
FireEyeGeneric.mg.fc0d34cd32fbadac
CAT-QuickHealTrojan.RaccryptPMF.S25811312
ALYacGen:Variant.Jaik.49985
ZillyaTrojan.Kryptik.Win32.3667454
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058c5671 )
K7GWTrojan ( 0058c5671 )
Cybereasonmalicious.432a7e
CyrenW32/Kryptik.FWV.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HNVD
TrendMicro-HouseCallMal_Tofsee
ClamAVWin.Dropper.Lockbit-9917808-0
BitDefenderGen:Variant.Jaik.49985
RisingSpyware.Stealer!8.3090 (C64:YzY0OscHG9f7Qfz5)
EmsisoftGen:Variant.Jaik.49985 (B)
DrWebTrojan.Siggen16.20244
TrendMicroMal_Tofsee
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SophosML/PE-A + Mal/Agent-AWV
APEXMalicious
JiangminTrojanSpy.Stealer.mke
Antiy-AVLTrojan/Generic.ASMalwS.35047A5
MicrosoftRansom:Win32/StopCrypt.MZD!MTB
GDataGen:Variant.Jaik.49985
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.GEE.C4869934
McAfeeLockbit-FSWW!FC0D34CD32FB
MAXmalware (ai score=89)
VBA32BScope.Trojan.Convagent
MalwarebytesMalware.AI.393240895
YandexTrojan.Kryptik!KxYT7pYN6e8
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HOCG!tr
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.393240895?

Malware.AI.393240895 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment