Malware

Should I remove “Malware.AI.2177379037”?

Malware Removal

The Malware.AI.2177379037 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2177379037 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Malware.AI.2177379037?


File Info:

name: E823C4FA6FA8C34401D7.mlw
path: /opt/CAPEv2/storage/binaries/794ced8544476b6bbba221415806c209d34cb3425de56ae00d6bd529431f00f2
crc32: 30A04D10
md5: e823c4fa6fa8c34401d7d8c556fa4d3a
sha1: 5e057c5681600beed0bb4fc3f82a0f99014c1a4b
sha256: 794ced8544476b6bbba221415806c209d34cb3425de56ae00d6bd529431f00f2
sha512: e5ce4f7b81a4cadbb327a8e94ac5585c725a6f98c135015a6082c7e1ec7aa6411280a2be443dc99af586f4712380ced0b56d8b98303eb8c7dcd7522ff3159410
ssdeep: 24576:1OYzhL2KtzLMNq3szV1+bTjhwZQ7u6nt5tG0eLjFvEv:1OChLXqq8zV4T6ZQ7u6tQLjFvW
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BC455B80FA878DF7D927023686C7E32F173DE6415717CF57EA18A8399B136A23A85341
sha3_384: 3e4c5a540dbecf293dedbcdc2615ecd09737db3e83e1f47b688f029328be345650713fe9440b510414ef2d769ac42922
ep_bytes: 83ec0cc705f8be490000000000e8dea0
timestamp: 2019-04-11 18:50:41

Version Info:

0: [No Data]

Malware.AI.2177379037 also known as:

LionicTrojan.Win32.Mettle.4!c
Elasticmalicious (high confidence)
CylanceUnsafe
K7AntiVirusTrojan ( 0055c8151 )
AlibabaTrojan:Win32/Mettle.2c363e5a
K7GWTrojan ( 0055c8151 )
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/Mettle.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Mettle.A
CynetMalicious (score: 99)
AvastWin32:Trojan-gen
McAfee-GW-EditionBehavesLike.Win32.BadFile.th
SophosMal/Generic-S
IkarusTrojan.Win32.Mettle
GDataWin32.Trojan.Mettle.A
AviraTR/Redcap.vijff
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!E823C4FA6FA8
VBA32BScope.Backdoor.Win64.Meterpreter
MalwarebytesMalware.AI.2177379037
TrendMicro-HouseCallTROJ_GEN.R002H0CKU21
YandexTrojan.GenAsa!9NNuV26sdJ8
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Mettle.A!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.681600

How to remove Malware.AI.2177379037?

Malware.AI.2177379037 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment