Malware

How to remove “Malware.AI.2241193407”?

Malware Removal

The Malware.AI.2241193407 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Malware.AI.2241193407 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Installs a browser addon or extension
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Farsi
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Operates on local firewall’s policies and settings
  • Attempts to disable or modify the Run command from the Start menu and the New Task (Run) command from Task Manager
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine Malware.AI.2241193407?


File Info:

name: 1A3DBC239EDEADF5F3BD.mlw
path: /opt/CAPEv2/storage/binaries/d48ad38f714e12b537e3dd51a994807b016a80b20a335c64f6c62154a4cc75fe
crc32: BAA45437
md5: 1a3dbc239edeadf5f3bd8aa972ab9d3c
sha1: e95647edcdfeea0be19fb5628a3272bc05521a9b
sha256: d48ad38f714e12b537e3dd51a994807b016a80b20a335c64f6c62154a4cc75fe
sha512: 53c3e4b6b61b1e0885137c56e083be9150237ae55922668c018ad1049120c70601c8e98559a771afa3e3a9bb088aa65fefdf87baafa84484e20408a9a56919c7
ssdeep: 3072:OmqtkjEgIN9thOU2t28JKfjXnyIpGXJK2jxcis0:lqtsEFOUkJ8fGXJ4is
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19CE34C47F7401241E69D563008BB8B4453637C3BAE732ADB25A0B7662DF3A431E26E5F
sha3_384: 311a5f60d61538553d0677c0ed0a98d32204c9df7beb605e87d862595403a36c3d5ac752a72f4c941b37b16fba6721bd
ep_bytes: 68f4174000e8eeffffff000000000000
timestamp: 2009-12-25 10:41:25

Version Info:

Translation: 0x0409 0x04b0
ProductName:
FileVersion: 4.10.0098
ProductVersion: 4.10.0098
InternalName: Diaco
OriginalFilename: Diaco.exe

Malware.AI.2241193407 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.im1@sbqGBXaO
ClamAVWin.Dropper.Cosmu-7566426-0
CAT-QuickHealTrojan.CosmuMF.S20620071
McAfeeGeneric.bow
CylanceUnsafe
VIPREGen:Trojan.Heur.im1@sbqGBXaO
SangforSuspicious.Win32.Save.vb
K7AntiVirusP2PWorm ( 0055e3ea1 )
AlibabaTrojan:Win32/udisk.ali1000021
K7GWP2PWorm ( 0055e3ea1 )
Cybereasonmalicious.39edea
VirITTrojan.Win32.Generic.BOSF
CyrenW32/Risk.XUFU-6730
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/VB.OYX
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Cosmu.dqm
BitDefenderGen:Trojan.Heur.im1@sbqGBXaO
NANO-AntivirusTrojan.Win32.Cosmu.ebpidw
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10ce3cce
Ad-AwareGen:Trojan.Heur.im1@sbqGBXaO
SophosML/PE-A + Mal/VBbl-PN
ComodoTrojWare.Win32.Cosmu.K@1x7b2b
DrWebTrojan.AVKill.2304
ZillyaTrojan.Cosmu.Win32.3121
TrendMicroWORM_COSMU.SMD
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.1a3dbc239edeadf5
EmsisoftGen:Trojan.Heur.im1@sbqGBXaO (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Cosmu.pub
WebrootW32.Downloader.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Cosmu
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Heur.EFD1FC7
ViRobotTrojan.Win32.Cosmu.143367
GDataGen:Trojan.Heur.im1@sbqGBXaO
GoogleDetected
AhnLab-V3Trojan/Win32.Cosmu.R638
VBA32Trojan.Cosmu
ALYacGen:Trojan.Heur.im1@sbqGBXaO
MAXmalware (ai score=100)
MalwarebytesMalware.AI.2241193407
TrendMicro-HouseCallWORM_COSMU.SMD
RisingTrojan.Ymacco!8.11BE1 (TFE:3:HBA1zaaL5QP)
YandexTrojan.GenAsa!rdoMSj4lbvE
IkarusTrojan.Win32.Malagent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Cosmu.SMD!worm
BitDefenderThetaAI:Packer.417D04801C
AVGWin32:Malware-gen
PandaW32/OverDoom.B.worm
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2241193407?

Malware.AI.2241193407 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment