Malware

Malware.AI.2131602206 removal

Malware Removal

The Malware.AI.2131602206 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2131602206 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the shellcode patterns malware family
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Malware.AI.2131602206?


File Info:

name: C6033DCCB4C92544CF8E.mlw
path: /opt/CAPEv2/storage/binaries/382e2ba356984b597563d98923e9fbe03c979d1d7a31a460d01645eae90d9911
crc32: F8F2E1F3
md5: c6033dccb4c92544cf8eac69eaaccea1
sha1: 4b94ce08cd643af203807a8b548d3ffefe7cef12
sha256: 382e2ba356984b597563d98923e9fbe03c979d1d7a31a460d01645eae90d9911
sha512: ab54d56e6dd2a1b09df2624577dfd6f4ad78971318e39aaab9f200d27e6588b9c4098f29339711167358a4aa1012aec2d8cb4f8943bb284f290714db709603d7
ssdeep: 1536:V3cpyORJLuB4P4AJJv4Romu/gYF5XCcx7icBbMVMEx:V3c1fP4AJJv45sCcx7JBb/Ex
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15A53CF1A32C1D4BBD967523199738B7AE3F79B01236256832B24AF7F2D31087D927581
sha3_384: cae6f540afed83f459bcdd356ec945ec53614f6bb16dd1206352d46e86ac17eed33c31860aedadde3adff836db1b1f07
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-06-18 21:33:27

Version Info:

0: [No Data]

Malware.AI.2131602206 also known as:

BkavW32.AIDetectMalware
LionicTrojan.NSIS.Agent.lomr
AVGNSIS:StartPage-AK [Drp]
DrWebTrojan.StartPage.34355
MicroWorld-eScanDropped:Generic.Startpage.10.538E1727
FireEyeDropped:Generic.Startpage.10.538E1727
CAT-QuickHealTrojan.NSIS.Startpage.DV
SkyhighStartPage-NQ
McAfeeArtemis!C6033DCCB4C9
MalwarebytesMalware.AI.2131602206
VIPREDropped:Generic.Startpage.10.538E1727
SangforPUP.Win32.StartPage.Vgaq
AlibabaTrojanDropper:Win32/StartPage.b47dfd75
K7GWTrojan ( 00547c921 )
K7AntiVirusTrojan ( 00547c921 )
VirITTrojan.Win32.StartPage.BYVJ
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32NSIS/StartPage.AP
CynetMalicious (score: 99)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.NSIS-32
KasperskyTrojan-Dropper.Win32.StartPage.dvq
BitDefenderDropped:Generic.Startpage.10.538E1727
NANO-AntivirusTrojan.Win32.StartPage.eljgc
AvastNSIS:StartPage-AK [Drp]
EmsisoftDropped:Generic.Startpage.10.538E1727 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduNSIS.Trojan.StartPage.e
ZillyaDropper.StartPage.Win32.2147
TrendMicroTROJ_STARTP.SMHU
Trapminesuspicious.low.ml.score
SophosMal/StartP-AM
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Startpage.Gen
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/NSIS.StartPage.ap
MicrosoftTrojan:Win32/Startpage!pz
XcitiumTrojWare.Win32.Agent.giyt@3cwvfp
ArcabitGeneric.Startpage.10.538E1727
ViRobotDropper.A.StartPage.66490.DD
ZoneAlarmTrojan-Dropper.Win32.StartPage.dvq
GDataDropped:Generic.Startpage.10.538E1727
VaristW32/Zlob.AF.gen!Eldorado
AhnLab-V3Trojan/Win32.Agent.R9483
ALYacDropped:Generic.Startpage.10.538E1727
VBA32Trojan.StartPage
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallHV_ZYX_BH01027E.TOMC
TencentTrojan.Win32.Startpage.OD
YandexNSIS.Startpage.Gen.20
IkarusTrojan-Dropper.Win32.StartPage
FortinetW32/StartPage.BX!tr.NSIS
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/StartPage.AP

How to remove Malware.AI.2131602206?

Malware.AI.2131602206 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment