Malware

Malware.AI.2253941064 removal guide

Malware Removal

The Malware.AI.2253941064 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.2253941064 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Created a process from a suspicious location
  • CAPE detected the NetWire malware family

How to determine Malware.AI.2253941064?


File Info:

name: E5D9F595800635403002.mlw
path: /opt/CAPEv2/storage/binaries/593557381e6b814ba93dada2bef66e270c1fc7cc86a3469203804e4bbb330f9c
crc32: F7DF8B23
md5: e5d9f595800635403002e896e3bd2f19
sha1: 4e8bb1eeaa1110f1187c54ad597b683933f27795
sha256: 593557381e6b814ba93dada2bef66e270c1fc7cc86a3469203804e4bbb330f9c
sha512: 0fc414fb5544509fbc56c417a5c76ef887daa877b0cf916525c0fd44776c483e4bc9eabb29f339a21bf6b91c03650fbd1669c28b00dc3b3da2155d850809186b
ssdeep: 6144:rGisj64lTXUXbe+nc5uSOL1LNxcGk8PSzAKXF:2EXC0SOxLf1kDAK1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DF642295E2C09C5BDB9E453379B2C366FBB9D1F60262BED38F814FDA19224358315223
sha3_384: fcefb0d90c2e44ead081b7213225e3a7216bdfeddf3e76401d82e98465b1afddf5fd6c75151b3978f954a121a83a005d
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-10-10 21:49:01

Version Info:

0: [No Data]

Malware.AI.2253941064 also known as:

LionicTrojan.Win32.Generic.4!c
DrWebBackDoor.Wirenet.557
MicroWorld-eScanTrojan.GenericKD.38237589
FireEyeTrojan.GenericKD.38237589
CAT-QuickHealTrojan.IGENERIC
McAfeeRDN/Generic BackDoor
CylanceUnsafe
SangforBackdoor.Win32.NetWiredRC.gen
K7AntiVirusTrojan ( 0058b69a1 )
AlibabaBackdoor:Win32/Lokibot.00194660
K7GWTrojan ( 0058b69a1 )
Cybereasonmalicious.580063
CyrenW32/Injector.ANJ.gen!Eldorado
SymantecPacked.Generic.606
ESET-NOD32a variant of Win32/Injector.EQRS
TrendMicro-HouseCallTROJ_GEN.R049C0DL821
Paloaltogeneric.ml
KasperskyTrojan.Win32.Inject.anzqj
BitDefenderTrojan.GenericKD.38237589
AvastWin32:PWSX-gen [Trj]
Ad-AwareTrojan.GenericKD.38237589
SophosMal/Generic-S
Comodofls.noname@0
ZillyaBackdoor.NetWiredRC.Win32.2396
TrendMicroTROJ_GEN.R049C0DL821
McAfee-GW-EditionRDN/Generic BackDoor
EmsisoftTrojan.GenericKD.38237589 (B)
IkarusTrojan.NSIS.Agent
GDataWin32.Backdoor.NetWireRC.RDXUCU
AviraHEUR/AGEN.1141486
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2477595
ViRobotTrojan.Win32.Z.Injector.321827
MicrosoftTrojan:Win32/Lokibot.SIS!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.BackDoor.C4871676
VBA32Backdoor.NetWiredRC
ALYacTrojan.GenericKD.38237589
MalwarebytesMalware.AI.2253941064
APEXMalicious
MAXmalware (ai score=89)
FortinetW32/Injector.EQTC!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Malware.AI.2253941064?

Malware.AI.2253941064 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment