Malware

Should I remove “Malware.AI.1974689238”?

Malware Removal

The Malware.AI.1974689238 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.1974689238 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Malware.AI.1974689238?


File Info:

name: 44D89DF9D1E3C47E8FC9.mlw
path: /opt/CAPEv2/storage/binaries/5b3d8fe9af65e6b4570178c69987735a4480a7733008d1ad836d657aad211ce6
crc32: 9B98D33D
md5: 44d89df9d1e3c47e8fc9e7b4a006cd7d
sha1: a56742d663e8f0743aeeac7036e0305ec921c9d9
sha256: 5b3d8fe9af65e6b4570178c69987735a4480a7733008d1ad836d657aad211ce6
sha512: 2e6f34cda5036b39886e9feb269e689d5898b2abc36c51f32a8d73b33c6561c5eb58408d7c64612993dc10ff88ebb79faec320c128160bdf1762a9a6ba068f18
ssdeep: 12288:ZrlIvDx+jrn/JHTDzUvMj6Qm62uhfD6C/I:Zl6E9TPUEOQmTC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DFA4D024B6D490F3E1DB11B61975C3E5AA6679F17241A09F7FCB0FB80B346D2922C34A
sha3_384: 8b15ff9fc9a7e2565e9cfdbf7fd631c7b0db46f6e124cb02016936f48fd9eeb9db056e211249438eff6dcea3fab5a7b9
ep_bytes: e8a3c7ffffe989feffff578bc683e00f
timestamp: 2012-04-03 20:42:09

Version Info:

0: [No Data]

Malware.AI.1974689238 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.487972
MalwarebytesMalware.AI.1974689238
Cybereasonmalicious.663e8f
BitDefenderThetaAI:Packer.C9A18CBB1F
CyrenW32/SoftPulse.CR.gen!Eldorado
ESET-NOD32a variant of Win32/Patched.NKM
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Convagent.gen
BitDefenderGen:Variant.Zusy.487972
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10bf205a
EmsisoftGen:Variant.Zusy.487972 (B)
DrWebWin32.Beetle.2
VIPREGen:Variant.Zusy.487972
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.44d89df9d1e3c47e
IkarusTrojan.Win32.Krypt
GoogleDetected
Antiy-AVLTrojan/Win32.GenKryptik
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Zusy.D77224
GDataGen:Variant.Zusy.487972
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5481402
VBA32BScope.TrojanDownloader.Emotet
ALYacGen:Variant.Zusy.487972
MAXmalware (ai score=83)
RisingTrojan.Generic@AI.100 (RDML:U4NYsIxbj266a38bfg5QvQ)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Patched.IP!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Malware.AI.1974689238?

Malware.AI.1974689238 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment