Malware

Malware.AI.2028257381 removal instruction

Malware Removal

The Malware.AI.2028257381 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2028257381 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Malware.AI.2028257381?


File Info:

crc32: E4C6606C
md5: a0cc8583c99ac5bde4e3d5e56f19e16d
name: A0CC8583C99AC5BDE4E3D5E56F19E16D.mlw
sha1: 6bf420630ea93998923b0a702b2af4889ef0e7fc
sha256: 761aeddc45267c21301b55a476426fe32f19355b1dbcc04ec7a31942f3f3b4ec
sha512: 46a3ea3cb94f4a9c20686552dab4e327da68449237a81e801fc8102f31788f77261832593dee70c4c39727242942f610645526f20e63d0173c9b3d22f75d93e8
ssdeep: 1536:bLtRDwJlStGNV1NLm1PRN4L8HZ5hLggdCyOV/KlrjDLXn6vH:bLr6ktGNvNCh4oHZTggdZOglTLXn6vH
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

InternalName: NirCmd
FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b0

Malware.AI.2028257381 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f8bc31 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.Crowti.MUE.A6
ALYacGen:Variant.Ransom.CryptXXX.1
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004f8bc31 )
Cybereasonmalicious.3c99ac
CyrenW32/S-b5a1ff1e!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.HGEN
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Goblinek [Inf]
KasperskyHEUR:Trojan-Ransom.Win32.Agent.pef
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusTrojan.Win32.Kryptik.evhhca
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentMalware.Win32.Gencirc.10b58bdf
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S
ComodoMalCrypt.Indus!@1qrzi1
BitDefenderThetaGen:NN.ZexaF.34110.gy0@a0nHCYbU
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.a0cc8583c99ac5bd
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
AviraHEUR/AGEN.1128192
eGambitUnsafe.AI_Score_91%
Antiy-AVLTrojan/Generic.ASMalwS.22C4F97
MicrosoftTrojan:Win32/Ditertag.A
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Trojan/Win32.CryptXXX.C1567206
Acronissuspicious
McAfeeRansomware-FTK!A0CC8583C99A
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.2028257381
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingTrojan.Generic@ML.100 (RDML:k5rJGoTPhQHm0YwUj/AZBA)
YandexTrojan.GenAsa!rPlCHhCY5Gw
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Goblinek [Inf]
Paloaltogeneric.ml

How to remove Malware.AI.2028257381?

Malware.AI.2028257381 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment