Malware

Malware.AI.2068113442 removal

Malware Removal

The Malware.AI.2068113442 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2068113442 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • A script process created a new process
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.2068113442?


File Info:

name: DDDD77F42BFB365F3676.mlw
path: /opt/CAPEv2/storage/binaries/bf90d5db47e6ba3a1840976b6bb88a8d0dfe97dfe02c9ca31b7be4018816d232
crc32: DE1BB32C
md5: dddd77f42bfb365f36762ad4db4a741e
sha1: f963db990278bcfc06bae64b89ebaf3484b4ade8
sha256: bf90d5db47e6ba3a1840976b6bb88a8d0dfe97dfe02c9ca31b7be4018816d232
sha512: 97eea025cc453b98e23a5043a6ffc5734d2c9964a2ae0d36c6ff453d60c143f2772d4e36cfa0d1188d262874af3dcd0d3d0ead93a2b1b03f0842397a6035c0e7
ssdeep: 12288:rc2pIrhOR3Ja3x3kSvM6aQ60naQgZ+g8mL7Nar3LDpNf8CBP:rc2Sssh7M9NAuwjpNnF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BEB4E01237D3C878C5511571C8AA67B8A6B9FD208B8093C363907F0FBEB45C8D97E696
sha3_384: a9b94771211347260e307f35eda43c6482e567e252720b6f404c63533489d0d955f8571b398e3a8b28022a095122d6f9
ep_bytes: 558bec6aff6828a04100685069410064
timestamp: 2010-11-16 12:21:25

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.5.0.1937
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2010 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: November 16, 2010
ProductName: 7-Zip SFX
ProductVersion: 1.5.0.1937
Translation: 0x0000 0x04b0

Malware.AI.2068113442 also known as:

LionicTrojan.Win32.Gamaredon.4!c
DrWebTrojan.Siggen17.17352
ClamAVWin.Malware.Pterodo-9780421-0
CAT-QuickHealTrojan.Win32CiR
McAfeeGeneric pws.afg
CylanceUnsafe
SangforTrojan.Win32.Gamaredon.gen
K7AntiVirusTrojan ( 0058203f1 )
BitDefenderTrojan.Agent.DEFX
K7GWTrojan ( 0058203f1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Agent.ADGE-4046
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Pterodo.BAS.gen
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Gamaredon.gen
AlibabaTrojan:Win32/Gamaredon.42d2be5c
MicroWorld-eScanTrojan.Agent.DEFX
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11ebfedb
Ad-AwareTrojan.Agent.DEFX
EmsisoftTrojan.Agent.DEFX (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.DESSERTDOWN.YACBQ
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
FireEyeGeneric.mg.dddd77f42bfb365f
SophosMal/Generic-S + Troj/Mdrop-JNS
GDataTrojan.Agent.DEFX
JiangminTrojan.Gamaredon.g
WebrootW32.Trojan.Gen
AviraVBS/Agent.gvzeo
Antiy-AVLTrojan/Generic.ASMalwS.2816222
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Agent.DEFX
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Agent.C4660502
VBA32TrojanDropper.Gamaredon
ALYacTrojan.Agent.Pterodo
MAXmalware (ai score=86)
MalwarebytesMalware.AI.2068113442
TrendMicro-HouseCallTrojan.Win32.DESSERTDOWN.YACBQ
RisingTrojan.Pterodo!8.E528 (TOPIS:E0:oEXM0YM2HCB)
MaxSecureTrojan.Malware.300983.susgen
FortinetVBS/SAgent!tr
AVGWin32:Malware-gen
Cybereasonmalicious.42bfb3

How to remove Malware.AI.2068113442?

Malware.AI.2068113442 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment