Malware

How to remove “Malware.AI.68034796”?

Malware Removal

The Malware.AI.68034796 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.68034796 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the CryptBot malware family
  • Anomalous binary characteristics

How to determine Malware.AI.68034796?


File Info:

name: CE626F6301F478E86B5B.mlw
path: /opt/CAPEv2/storage/binaries/17fa6e2f038bc3c832ea7f8162b33d12e3fdab5922f7ade51937c23b2eaaf0cd
crc32: E7C8CF79
md5: ce626f6301f478e86b5b4a832092a320
sha1: 884f6f8d8bee970b83b5c0f3af0bbb7be18873ba
sha256: 17fa6e2f038bc3c832ea7f8162b33d12e3fdab5922f7ade51937c23b2eaaf0cd
sha512: 63b383a0c74a822f97af08048edd99c5a5856decfafd058412738fef0644f0f28977a8a10eb7ac330e1becb204cbdc4a567777b87d52996482c9cd6634df984a
ssdeep: 6144:3QttpqFvbkTvtImforfelwHlWNuyTeu3DVJBF:3QPpqFvbkTvtImforf8wHlWblnBF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F46408927214FC06D0884530CD9BCAF80910BD57CA461AAB3BF07F1FFE766A3A9D6459
sha3_384: b6abf702d2e1ed90beb63d2e6f0d04e59f2a8ec57f382b02c9fa10f63ba9b8fe36d78c635a2d4b7405651fd73da1cfbe
ep_bytes: 8bd88bc88bd1ff15675740008bc86800
timestamp: 1970-01-01 00:00:00

Version Info:

FileVersion: 2, 5, 8, 2
Comments: Unordinariness
CompanyName: Star Force
FileDescription: Parthenic
InternalName: Toparch
PrivateBuild: Silked
Translation: 0x0409 0x04e4

Malware.AI.68034796 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed.20771
MicroWorld-eScanTrojan.GenericKD.38874255
FireEyeGeneric.mg.ce626f6301f478e8
McAfeeRDN/GenericTS
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3684078
SangforTrojan.Win32.GenericKD.38874255
K7AntiVirusTrojan ( 0058d90a1 )
K7GWTrojan ( 0058d90a1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.FSK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HODU
TrendMicro-HouseCallTROJ_FRS.VSNTAR22
AvastWin32:CrypterX-gen [Trj]
BitDefenderTrojan.GenericKD.38874255
Ad-AwareTrojan.GenericKD.38874255
EmsisoftTrojan.GenericKD.38874255 (B)
ComodoMalware@#tgf3aof3e067
TrendMicroTROJ_FRS.VSNTAR22
McAfee-GW-EditionRDN/GenericTS
SophosMal/Generic-S
Paloaltogeneric.ml
GDataTrojan.GenericKD.38874255
AviraTR/AD.GenSteal.nhrsy
ViRobotTrojan.Win32.Z.Packed.312476
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R472816
Acronissuspicious
VBA32Trojan.Packed
ALYacTrojan.GenericKD.38874255
MAXmalware (ai score=85)
MalwarebytesMalware.AI.68034796
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.139086275.susgen
FortinetW32/Kryptik.HODI!tr
WebrootW32.Malware.Gen
AVGWin32:CrypterX-gen [Trj]
PandaTrj/Agent.CTG

How to remove Malware.AI.68034796?

Malware.AI.68034796 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment