Malware

AIT.Heur2.Miner.5.EAE43AA0.Gen information

Malware Removal

The AIT.Heur2.Miner.5.EAE43AA0.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT.Heur2.Miner.5.EAE43AA0.Gen virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine AIT.Heur2.Miner.5.EAE43AA0.Gen?


File Info:

name: 8AF210809398DF789598.mlw
path: /opt/CAPEv2/storage/binaries/16258bc6de4edba458f10c08a53caa353223c89c41845f340fa0d0988e7a7963
crc32: 12718B1D
md5: 8af210809398df7895983099b4179665
sha1: eaba3629074d91287bf71e63e93b42c1cc363941
sha256: 16258bc6de4edba458f10c08a53caa353223c89c41845f340fa0d0988e7a7963
sha512: f8f106a7c24740cb6d9b4634b610d71b7bf2be21ed7f7f36692c6a63da8bf15ac1f830de94c0c528ea8665508c29292e75856e7c78bebb0a6d46590a5d15d455
ssdeep: 196608:cCKR4ojDcpaMW3WZVF6Cfi57zofp55YWaEGBom3h4jhaia:X64yY0Mu46Cf4Ufr5UPREP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18776231373D6C066FFAB92739F66B20466BC79640137C52F23981D79BC705A2263E623
sha3_384: cf0bdc66dd6ef52478c278f2ba1bc40f56d121bcf183160460dd5af65f5794bcfe5e30a1b131e3fcd60b9e748f132571
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2021-03-09 18:11:30

Version Info:

Translation: 0x0809 0x04b0

AIT.Heur2.Miner.5.EAE43AA0.Gen also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Miner.4!c
tehtrisGeneric.Malware
MicroWorld-eScanAIT.Heur2.Miner.5.EAE43AA0.Gen
FireEyeGeneric.mg.8af210809398df78
ALYacAIT.Heur2.Miner.5.EAE43AA0.Gen
CylanceUnsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 005797341 )
AlibabaPacked:Win32/Generic.1509a994
K7GWTrojan ( 005797341 )
Cybereasonmalicious.09398d
CyrenW32/AutoIt.UN.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.AutoIt.UX
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Miner.bdq
BitDefenderAIT.Heur2.Miner.5.EAE43AA0.Gen
NANO-AntivirusTrojan.Win32.Miner.joeyvi
AvastBV:CoinHelper-D [Miner]
TencentWin32.Trojan.Miner.Mjgl
Ad-AwareAIT.Heur2.Miner.5.EAE43AA0.Gen
EmsisoftAIT.Heur2.Miner.5.EAE43AA0.Gen (B)
DrWebTrojan.AutoIt.964
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win64.Autoit
GDataAIT.Heur2.Miner.5.EAE43AA0.Gen (2x)
AviraHEUR/AGEN.1245611
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3CoinMiner/AU3.Generic.S1299
Acronissuspicious
McAfeeArtemis!8AF210809398
MAXmalware (ai score=89)
MalwarebytesTrojan.BitCoinMiner.AutoIt
MaxSecureTrojan.Malware.117654446.susgen
FortinetAutoIt/Miner.BDE!tr
AVGBV:CoinHelper-D [Miner]

How to remove AIT.Heur2.Miner.5.EAE43AA0.Gen?

AIT.Heur2.Miner.5.EAE43AA0.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment