Malware

Malware.AI.2189396088 (file analysis)

Malware Removal

The Malware.AI.2189396088 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2189396088 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk

How to determine Malware.AI.2189396088?


File Info:

name: CCDC439EA2C6871BC478.mlw
path: /opt/CAPEv2/storage/binaries/4350c0a6c884b95c4727d576dbad736f4583d13fc76adab2ab6db3220f8d8707
crc32: C3CB8FB7
md5: ccdc439ea2c6871bc4786b534456027d
sha1: bb68e17696a5b0cfe86bb97254ba8bcb2974723f
sha256: 4350c0a6c884b95c4727d576dbad736f4583d13fc76adab2ab6db3220f8d8707
sha512: 685806a8e22802508a0304feb66cd2b1107d089d5d268f2682a0dea93900b7c972bc0ca6a5a7c27eecf8bc844bbb3b9fc4ab51c1ff9650f241b0bae7bab2debb
ssdeep: 1536:P7fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfmwlHEwjs4Ov:j7DhdC6kzWypvaQ0FxyNTBfm+k+s7
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13CB34B41B2D1C2FBEDE24531D05662FA97376E28C76098DBC78C3E4279329C5963D2E8
sha3_384: f7eded64605cad708b33f4c5840dad960d9e08ac2e2bb21bbd1b75a5b30366c4ef130bcad89b2c84a303645cdb4cdbfb
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
ProductName: Installateur compte MicroSIP
OriginalFilename: Installateur compte MicroSIP
InternalName: Installateur compte MicroSIP
FileDescription: Installateur compte MicroSIP
CompanyName: WinToz
LegalCopyright: WinToz
Translation: 0x0000 0x04e4

Malware.AI.2189396088 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.67873441
FireEyeGeneric.mg.ccdc439ea2c6871b
SkyhighBehavesLike.Win32.RealProtect.ch
ALYacTrojan.GenericKD.67873441
MalwarebytesMalware.AI.2189396088
SangforTrojan.Win32.Save.a
BitDefenderTrojan.GenericKD.67873441
APEXMalicious
ClamAVWin.Trojan.Generic-10011119-0
RisingTrojan.Generic@AI.99 (RDML:W0KXF6mXEp0JJ/hqhAcSmg)
EmsisoftTrojan.GenericKD.67873441 (B)
VIPRETrojan.GenericKD.67873441
SophosGeneric ML PUA (PUA)
MAXmalware (ai score=86)
JiangminTrojan.BAT.aww
GoogleDetected
VaristW32/ABTrojan.PWAK-6028
ArcabitTrojan.Generic.D40BAAA1
GDataTrojan.GenericKD.67873441
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5249026
McAfeeRDN/Generic.dx
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H06J323
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.218245754.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.36792.gu0@aeUaG!o
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Malware.AI.2189396088?

Malware.AI.2189396088 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment