Malware

Malware.AI.2116695780 (file analysis)

Malware Removal

The Malware.AI.2116695780 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2116695780 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup

Related domains:

fget-career.com

How to determine Malware.AI.2116695780?


File Info:

crc32: 2C32E81F
md5: 2e6242fd727f86482eabab54be2943ef
name: 2E6242FD727F86482EABAB54BE2943EF.mlw
sha1: 5b052e95ac7ae4c86fc5d1f7917a9676af1b6ca9
sha256: e3b6e8e62a2a55ef1727b8792b62ea0066605f53836352576f23019cafe2add5
sha512: ece9c7a6ae17094742bea451c974ecabc7340c4e7681d78b72fce1b4a9b203dc45c68b7774b25e810feecb69df80ab7d7c746e8a8ddb421778f3dbd349033ff1
ssdeep: 6144:1G8CW5wner/qgg9FSO2/wSfe43l4UTaRf8N4oS4POvaaA85f2X:1Bnwnevg7SO2Yt4HTa98qoSaR8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
LegalCopyright: ~~x7fc1x8f6fx5728x7ebf x521bx610fx65e0x9650~~
InternalName: ChipGenius_v4_18_0203
FileVersion: 4.18.0203
CompanyName: x6570x7801x4e4bx5bb6
LegalTrademarks: x54c8x5c14x6ee8x5de5x4e1ax5927x5b66x7814x7a76x751fx9662 x54c8x5c14x6ee8x7406x5de5x5927x5b66x8f6fx4ef6x4e0ex5faex7535x5b50x5b66x9662
Comments: x65b9x4fbfx5b9ex7528x7684USBx8bbex5907x4e3bx63a7x82afx7247x8bc6x522bx5de5x5177
ProductName: Chip Genius
ProductVersion: 4.18.0203
FileDescription: Ux76d8/MP3x4e3bx63a7x82afx7247x8bc6x522bx5de5x5177
OriginalFilename: ChipGenius_v4_18_0203.exe

Malware.AI.2116695780 also known as:

BkavW32.RammitNNA.PE
K7AntiVirusVirus ( 002fe95d1 )
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Ramnit-1847
CAT-QuickHealW32.Ramnit.A
ALYacWin32.Ramnit
CylanceUnsafe
ZillyaVirus.Nimnul.Win32.1
SangforWin.Trojan.Ramnit-1847
CrowdStrikewin/malicious_confidence_70% (D)
K7GWVirus ( 002fe95d1 )
Cybereasonmalicious.d727f8
BitDefenderThetaAI:FileInfector.EAEEA7850C
CyrenW32/Ramnit.B!Generic
SymantecW32.Ramnit!inf
ESET-NOD32Win32/Ramnit.A
ZonerTrojan.Win32.Ramnit.23698
APEXMalicious
AvastWin32:RmnDrp [Inf]
CynetMalicious (score: 100)
BitDefenderWin32.Ramnit
NANO-AntivirusVirus.Win32.Ramnit.eslalb
ViRobotWin32.Ramnit.E
MicroWorld-eScanWin32.Ramnit
Ad-AwareWin32.Ramnit
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebWin32.Rmnet
VIPREVirus.Win32.Ramnit.a (v)
TrendMicroPE_RAMNIT.H
McAfee-GW-EditionBehavesLike.Win32.Ramnit.fc
FireEyeGeneric.mg.2e6242fd727f8648
SophosML/PE-A + W32/Patched-I
SentinelOneStatic AI – Suspicious PE
JiangminWin32/PatchFile.et
AviraW32/Ramnit.CD
Antiy-AVLTrojan/Generic.ASVirus.1EB
GridinsoftMalware.Win32.Gen.bot!se59456
GDataWin32.Virus.Ramnit.C
TACHYONVirus/W32.Ramnit.B
AhnLab-V3Win32/Ramnit.B
McAfeeW32/Ramnit.q
MAXmalware (ai score=87)
VBA32Virus.Win32.Nimnul.a
MalwarebytesMalware.AI.2116695780
PandaW32/Cosmu.gen
TrendMicro-HouseCallPE_RAMNIT.H
TencentVirus.Win32.Nimnul.d
YandexWin32.Ramnit.Gen.3
IkarusVirus.Ramnit
MaxSecureVirus.Nimnul.A
FortinetW32/Ramnit.A
AVGWin32:RmnDrp [Inf]
Qihoo-360Virus.Win32.Ramnit.B

How to remove Malware.AI.2116695780?

Malware.AI.2116695780 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment