Malware

Malware.AI.2015491400 removal

Malware Removal

The Malware.AI.2015491400 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2015491400 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Malware.AI.2015491400?


File Info:

name: 3FD797842CE97EDD86B2.mlw
path: /opt/CAPEv2/storage/binaries/132d9e0b15c8ac94ecab5bb7c3120b9eb7006f65f4597b7c488218681b829e7d
crc32: BA3B2419
md5: 3fd797842ce97edd86b28303c4f5896a
sha1: 8809504d750e6ea847b5d56a137b22b42c920a4e
sha256: 132d9e0b15c8ac94ecab5bb7c3120b9eb7006f65f4597b7c488218681b829e7d
sha512: da3a8ae42e98d383bac094fb81c38de29e490cf8eb36fad6a90c8768a68470ad4da3eefc1b04a35c31afe4acd94e2a51391a7da08b4d2f5a2099168575c952e2
ssdeep: 24576:oSSlCe9qhJMylUNgPcAMWjAl0Pq7v1JTHpZkeX8ML9:ulCe9qhJFUOPcHWEl0PurT/7BL9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11145E163A1659F84DEB883F290651F4813A72D9E3971F16C0C9AB4E667F33C309529E3
sha3_384: b6bf0e53f43a2585ee8fb8a93d2d58f08f1f2b4257b4d83a6dc0b799b104aed567d939114af202e3c55677d64851570d
ep_bytes: ff250020400000000000000000000000
timestamp: 2087-02-19 09:17:57

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: QuanLyDichVuKhachSan
FileVersion: 1.0.0.0
InternalName: dVwU.exe
LegalCopyright: Copyright © 2023
LegalTrademarks:
OriginalFilename: dVwU.exe
ProductName: QuanLyDichVuKhachSan
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Malware.AI.2015491400 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.2290
MicroWorld-eScanTrojan.MSIL.Agent.FTB
FireEyeTrojan.MSIL.Agent.FTB
VIPRETrojan.MSIL.Agent.FTB
K7AntiVirusTrojan ( 005aa2a81 )
K7GWTrojan ( 005aa2a81 )
CyrenW32/MSIL_Agent.FPI.gen!Eldorado
SymantecScr.Malcode!gdn34
ESET-NOD32a variant of MSIL/GenKryptik.GNBC
KasperskyHEUR:Backdoor.MSIL.NanoBot.gen
BitDefenderTrojan.MSIL.Agent.FTB
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.13ecdd6c
EmsisoftTrojan.MSIL.Agent.FTB (B)
F-SecureTrojan.TR/Kryptik.ocsxa
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
SophosTroj/Krypt-ABO
SentinelOneStatic AI – Malicious PE
AviraTR/Kryptik.ocsxa
MicrosoftTrojan:Win32/Leonem
ZoneAlarmHEUR:Backdoor.MSIL.NanoBot.gen
GDataTrojan.MSIL.Agent.FTB
GoogleDetected
AhnLab-V3Trojan/Win32.Redlonam.R244789
MAXmalware (ai score=80)
MalwarebytesMalware.AI.2015491400
PandaTrj/GdSda.A
APEXMalicious
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:1NSdNlwfsW+8ODHWgmP43g)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.AJLO!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2015491400?

Malware.AI.2015491400 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment