Malware

What is “Malware.AI.920825772”?

Malware Removal

The Malware.AI.920825772 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.920825772 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.920825772?


File Info:

name: E5745E8D2349021507AC.mlw
path: /opt/CAPEv2/storage/binaries/e861d61374b668da732c7469d21c54f8a643c9f98ffd8582547183bfd1d36584
crc32: F048C573
md5: e5745e8d2349021507acde0ca1d1ed53
sha1: 77f35404407ecbf23dadfe8eb72674e4c442c22b
sha256: e861d61374b668da732c7469d21c54f8a643c9f98ffd8582547183bfd1d36584
sha512: ccbc7e2fb1bf8cd088c7eda00ba6120c85796dd9731b7880b201a0f5e3e020daf4f7a5bffa31575633976d153ba5cf17060511c9025e2810bdc12cb2dd559dff
ssdeep: 98304:eUvVuot4g11cTZUTnflkSuIj39NFj7xX3yTuY:1Vua1eUxkpIzzjH8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1690633122B3189BFE0694B321DA4951B52A4B0913D74872F7ECCFE9F8B047DBD586B06
sha3_384: a83dc5d6513a17bf01da780b6b0bed1f2d1b736ed9b48992aadb7824a9e506be019e4271a0b2874077ec00b4429aec41
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: HETach Setup
FileVersion:
LegalCopyright:
Translation: 0x0409 0x04e4

Malware.AI.920825772 also known as:

BkavW32.Common.906F7718
LionicTrojan.Win32.Ekstak.4!c
McAfeeArtemis!E5745E8D2349
Cylanceunsafe
SangforDropper.Win32.Ekstak.Vvdq
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.109aa2c7
K7GWTrojan ( 005722f11 )
CyrenW32/ABRisk.IYXA-0745
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Ekstak.anxwl
AvastWin32:Malware-gen
TencentWin32.Trojan.Ekstak.Usmw
F-SecureHeuristic.HEUR/AGEN.1332570
McAfee-GW-EditionBehavesLike.Win32.ObfuscatedPoly.wc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
GDataWin32.Backdoor.Bodelph.RT9TEO
JiangminTrojan.Ekstak.chvz
AviraHEUR/AGEN.1332570
ZoneAlarmTrojan.Win32.Ekstak.anxwl
AhnLab-V3Malware/Win.Malware-gen.R590054
MalwarebytesMalware.AI.920825772
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0DG823
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.212380198.susgen
FortinetW32/Agent.SLC!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.920825772?

Malware.AI.920825772 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment