Malware

Malware.AI.2241117924 malicious file

Malware Removal

The Malware.AI.2241117924 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2241117924 virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Malware.AI.2241117924?


File Info:

name: EC77B05FC6994544A5FD.mlw
path: /opt/CAPEv2/storage/binaries/accf31760f2516a36d6f026598e7874b62babf38470cbefae6e3892abab85c39
crc32: AB10F302
md5: ec77b05fc6994544a5fdd470d44223f4
sha1: ce12b032f68aecbe02941593398ce12055a1e0e3
sha256: accf31760f2516a36d6f026598e7874b62babf38470cbefae6e3892abab85c39
sha512: 5b7c0078a396bf74285cecc5acb999e58f8ac02809f40330647add863b29ef416b8cc08fb5db831d3206a5ff6a93a9fe99924d531a347965a71b2cb5270eaf51
ssdeep: 3072:W7wKt0ohwgLH24KDebjUrwkQI4pxSxt2fvLRY5YW+vPpcPzOFa:W7goJW4KGUskQIkHt1pcPzOF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F8048F628970BB16ED15093517A46BEA401D3C2F4BE9030DBCADDE5F3353DAA34AF942
sha3_384: a439611fa49b87b0b571e319b7214291351496589e99cb72b84ffcbc3e59b4621483b5ec245674cb9aedc12d52ee6b6d
ep_bytes: 68c0914200e8f0ffffff000000000000
timestamp: 2019-01-12 12:27:37

Version Info:

Translation: 0x0804 0x04b0
CompanyName: aaaa
ProductName: Kawaii-Unicorn
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Kawaii-Unicorn
OriginalFilename: Kawaii-Unicorn.exe

Malware.AI.2241117924 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop17.61497
MicroWorld-eScanGeneric.Dacic.94CCEEA9.A.41420625
FireEyeGeneric.mg.ec77b05fc6994544
CAT-QuickHealTrojan.MuldVMF.S21469993
ALYacGeneric.Dacic.94CCEEA9.A.41420625
VIPREGeneric.Dacic.94CCEEA9.A.41420625
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 004d83031 )
K7GWTrojan ( 004d83031 )
Cybereasonmalicious.fc6994
BitDefenderThetaAI:Packer.3C63DE941F
VirITTrojan.Win32.Banker1.BRRU
CyrenW32/S-8ed456b2!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/VBClone.D
APEXMalicious
ClamAVWin.Malware.Midie-6847892-0
KasperskyTrojan.Win32.VB.dosb
BitDefenderGeneric.Dacic.94CCEEA9.A.41420625
NANO-AntivirusTrojan.Win32.VB.fmvqeg
AvastWin32:VB-AJKU [Trj]
TencentTrojan.Win32.Vb.b
Ad-AwareGeneric.Dacic.94CCEEA9.A.41420625
SophosML/PE-A + Troj/VB-KCP
ComodoTrojWare.Win32.VBClone.B@88ji29
McAfee-GW-EditionBehavesLike.Win32.Rontokbro.cc
EmsisoftGeneric.Dacic.94CCEEA9.A.41420625 (B)
IkarusTrojan.VB.VBClone
GDataGeneric.Dacic.94CCEEA9.A.41420625
JiangminTrojan.VB.aqyg
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASBOL.C594
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R252862
McAfeeGenericRXHC-SS!EC77B05FC699
VBA32SScope.Trojan.VB
MalwarebytesMalware.AI.2241117924
RisingTrojan.VBClone!1.B5C7 (CLASSIC)
YandexTrojan.GenAsa!YDgvuUqpMd4
SentinelOneStatic AI – Malicious PE
AVGWin32:VB-AJKU [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Malware.AI.2241117924?

Malware.AI.2241117924 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment