Malware

Malware.AI.1491966407 removal

Malware Removal

The Malware.AI.1491966407 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1491966407 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Attempts to modify proxy settings

How to determine Malware.AI.1491966407?


File Info:

name: B270B34ABBA37E67A9AC.mlw
path: /opt/CAPEv2/storage/binaries/75c09a8a9b42810277e47f576c4d4f91067ad18f5196076f2aac1cc2f53b3973
crc32: C4E9ED68
md5: b270b34abba37e67a9ac4fa690a6b4ef
sha1: 6933c4f36da5d96b08603e60d739631a91c310e0
sha256: 75c09a8a9b42810277e47f576c4d4f91067ad18f5196076f2aac1cc2f53b3973
sha512: ef892045b2ecee515253392f33fcc66e1e187c70aa5d550772c2667afd2055d301a0e8220a5ccadf8bbcc80ca8332552a415dcea001b88d8918b90b513009182
ssdeep: 12288:Fr0UR9h0BN3J05wRWGBgbib5J79QvjlDjMzVkpSHNl2Jg:Fr0URPEJ0sg+9kqVkpSHeJg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B25E70277F99129F1F37BB1AEB893645A77BC71AD39C50E22C1215E09B4A40DA72733
sha3_384: 8fd5f9b4f55377593487ed2d29fbb207396efa902ae7861af4df37dae2f4b113a867af1963cddb7511e1e68142c0036c
ep_bytes: 558bec81ec68090000e8620c00008985
timestamp: 1970-01-01 15:50:05

Version Info:

CompanyName: Adobe Systems Incorporated
FileDescription: Adobe Reader and Acrobat Manager
FileVersion: 1.802.11.4130
InternalName: AdobeARM.exe
OriginalFilename: AdobeARM.exe
ProductName: Adobe Reader and Acrobat Manager
ProductVersion: 1.802.11.4130
Translation: 0x0409 0x04e4

Malware.AI.1491966407 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fugrafa.2379
FireEyeGeneric.mg.b270b34abba37e67
ALYacGen:Variant.Fugrafa.2379
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 00573e531 )
K7GWTrojan-Downloader ( 00573e531 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.34062.!y1@amIb7oli
CyrenW32/ZeroDloader.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.EQH
KasperskyTrojan.Win32.Patched.rw
BitDefenderGen:Variant.Fugrafa.2379
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Variant.Fugrafa.2379
EmsisoftGen:Variant.Fugrafa.2379 (B)
SophosML/PE-A
JiangminTrojanDownloader.Generic.beop
AviraW32/Infector.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.34D9536
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Fugrafa.2379
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R282625
TACHYONWorm/W32.ZeroDownloader
VBA32BScope.TrojanBanker.CliptoShuffler
MalwarebytesMalware.AI.1491966407
APEXMalicious
RisingTrojan.Generic@ML.99 (RDML:IImgkS4BWZbM/M9QhXe5NQ)
IkarusTrojan-Downloader.Win32.Agent
FortinetW32/Agent.EQH!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.abba37

How to remove Malware.AI.1491966407?

Malware.AI.1491966407 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment