Malware

Malware.AI.2143394658 information

Malware Removal

The Malware.AI.2143394658 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2143394658 virus can do?

  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Malware.AI.2143394658?


File Info:

name: 4009D737DB99FCE6C730.mlw
path: /opt/CAPEv2/storage/binaries/3757e94522b74c793b4aaa115806fbebd311c8eb7cdb9117b59e3ab69dd8cf23
crc32: ADBB2165
md5: 4009d737db99fce6c730dea40233d0c3
sha1: e1b78ae58c58dc55c331ddb495b37404a109ec1f
sha256: 3757e94522b74c793b4aaa115806fbebd311c8eb7cdb9117b59e3ab69dd8cf23
sha512: 8f7f61745a4653a3ae45d18bf20301fef0e4c3a209fc0d49a2afac186fb495988d9bfda1d458ac3e4d83d6b7f7989a8728d7edfab4ad0c6f5d1f776f9eeb0e3f
ssdeep: 6144:mK6g8IT6Jf+DdTwV/ky7n0FJcdyqRNew0OdVj844VCpBC8AwkPZ53w3gZAr4eM9Z:mK6FsQ/kyqMyqEwVgkBC8/sZmQZAe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T102A4120653E40632FEB217B418F815971E39B8A26FBA83CB77441DDA0C626D0A67477B
sha3_384: a49219812ec27c47d262dccf832aaefa9bd3948582040970fe6b0236eb6a9732560f18d4fcd1b5958d6ac47629d7e121
ep_bytes: e8d30b0000e905000000cccccccccc6a
timestamp: 2014-10-31 03:28:47

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Win32 Cabinet Self-Extractor
FileVersion: 11.00.9600.16384 (winblue_rtm.130821-1623)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.9600.16384
Translation: 0x0409 0x04b0

Malware.AI.2143394658 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.42273814
FireEyeGeneric.mg.4009d737db99fce6
ALYacTrojan.GenericKD.42273814
Cylanceunsafe
ZillyaTrojan.Generic.Win32.1016233
SangforTrojan.ASP.InjectorGen.ZB
K7AntiVirusTrojan ( 0056081c1 )
AlibabaTrojanDropper:Win32/InjectorGen.72a647c3
K7GWTrojan ( 0056081c1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/MSIL_Troj.RN.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.MSGEPAC
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.42273814
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Trojan.Generic.Fdhl
EmsisoftTrojan.GenericKD.42273814 (B)
F-SecureHeuristic.HEUR/AGEN.1314405
DrWebTrojan.PackedNET.260
VIPRETrojan.GenericKD.42273814
TrendMicroTrojanSpy.MSIL.AZORULT.SMA
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious SFX
GDataTrojan.GenericKD.42273814
AviraHEUR/AGEN.1314405
Antiy-AVLTrojan/MSIL.Kryptik
XcitiumMalware@#2tokzs7tdh7u3
ArcabitTrojan.Generic.D2850C16
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Generic.C3983163
McAfeeArtemis!4009D737DB99
MAXmalware (ai score=83)
MalwarebytesMalware.AI.2143394658
PandaTrj/CI.A
TrendMicro-HouseCallTrojanSpy.MSIL.AZORULT.SMA
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:aIQYBploLQNEyPqLNls/TA)
IkarusTrojan.MSIL.Crypt
FortinetMSIL/GenKryptik.EDWB!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Malware.AI.2143394658?

Malware.AI.2143394658 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment